CVE-2008-2812
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel · canonical/ubuntu linux · novell/linux desktop · opensuse/opensuse · suse/suse linux enterprise desktop · suse/suse linux enterprise server · debian/debian linux · avaya/communication manager · avaya/expanded meet-me conferencing · avaya/intuity audix lx · avaya/meeting exchange · avaya/message networking · avaya/messaging storage server · avaya/proactive contact · avaya/sip enablement services
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.25.y.git%3Ba=commitdiff%3Bh=2a739dd53ad7ee010ae6e155438507f329dce788
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.10Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00012.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/30982Broken Link
- http://secunia.com/advisories/31048Broken Link
- http://secunia.com/advisories/31202Broken Link
- http://secunia.com/advisories/31229Broken Link
- http://secunia.com/advisories/31341Broken Link
- http://secunia.com/advisories/31551Broken Link
- http://secunia.com/advisories/31614Broken Link
- http://secunia.com/advisories/31685Broken Link
- http://secunia.com/advisories/32103Broken Link
- http://secunia.com/advisories/32370Broken Link
- http://secunia.com/advisories/32759Broken Link
- http://secunia.com/advisories/33201Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2008-365.htmThird Party Advisory
- http://www.debian.org/security/2008/dsa-1630Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2008/07/03/2Mailing List, Patch, Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0612.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0665.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0973.htmlBroken Link
- http://www.securityfocus.com/bid/30076Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2063/referencesBroken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43687Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.