CVE-2008-2358
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html
- http://secunia.com/advisories/30000Vendor Advisory
- http://secunia.com/advisories/30818Vendor Advisory
- http://secunia.com/advisories/30849Vendor Advisory
- http://secunia.com/advisories/30920Vendor Advisory
- http://secunia.com/advisories/31107Vendor Advisory
- http://www.debian.org/security/2008/dsa-1592
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:112
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:167
- http://www.redhat.com/support/errata/RHSA-2008-0519.html
- http://www.securityfocus.com/bid/29603
- http://www.securitytracker.com/id?1020211
- http://www.ubuntu.com/usn/usn-625-1
- https://bugzilla.redhat.com/show_bug.cgi?id=447389
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9644
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00082.html
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html
- http://secunia.com/advisories/30000Vendor Advisory
- http://secunia.com/advisories/30818Vendor Advisory
- http://secunia.com/advisories/30849Vendor Advisory
- http://secunia.com/advisories/30920Vendor Advisory
- http://secunia.com/advisories/31107Vendor Advisory
- http://www.debian.org/security/2008/dsa-1592
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:112
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:167
- http://www.redhat.com/support/errata/RHSA-2008-0519.html
- http://www.securityfocus.com/bid/29603
- http://www.securitytracker.com/id?1020211
- http://www.ubuntu.com/usn/usn-625-1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.