Beveiligingsadvies

CVE-2008-4302

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2008-09-29 17:00:00
Laatst bijgewerkt 2024-08-07 10:08:35
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.