VulnerabilityModified
CVE-2008-0001
VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.
LOW 3.6EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=974a9f0b47da74e28f68b9c8645c3786aa5ace1a
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html
- http://rhn.redhat.com/errata/RHSA-2008-0055.html
- http://secunia.com/advisories/28485Vendor Advisory
- http://secunia.com/advisories/28558Vendor Advisory
- http://secunia.com/advisories/28626Vendor Advisory
- http://secunia.com/advisories/28628Vendor Advisory
- http://secunia.com/advisories/28643Vendor Advisory
- http://secunia.com/advisories/28664Vendor Advisory
- http://secunia.com/advisories/28706Vendor Advisory
- http://secunia.com/advisories/28748Vendor Advisory
- http://secunia.com/advisories/28806Vendor Advisory
- http://secunia.com/advisories/28971Vendor Advisory
- http://secunia.com/advisories/29245Vendor Advisory
- http://securitytracker.com/id?1019289
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021
- http://www.debian.org/security/2008/dsa-1479
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:044
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:112
- http://www.redhat.com/support/errata/RHSA-2008-0089.html
- http://www.securityfocus.com/archive/1/486485/100/0/threaded
- http://www.securityfocus.com/bid/27280Patch
- http://www.ubuntu.com/usn/usn-574-1
- http://www.ubuntu.com/usn/usn-578-1
- http://www.vupen.com/english/advisories/2008/0151Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39672
- https://issues.rpath.com/browse/RPL-2146
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.