CVE-2008-4302
29.09.2008, 17:17
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 < 2.6.22.2 |
debian | debian_linux | 4.0 |
redhat | enterprise_linux | 5.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||||
linux-source-2.6.15 |
| ||||||||||
linux-source-2.6.20 |
| ||||||||||
linux-source-2.6.22 |
|
Common Weakness Enumeration
References