HIGH
kernel: insufficient range checks in fault handlers with mremap
Published Feb 8, 2008
7.2
HIGHCVSS 2.0
EPSS 0.49%
Description
Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.
Affected products
No data.
- ≤ 2.6.22.16
No data.
Red Hat Enterprise Linux 2.1
kernel-0:2.4.18-e.67
Fixed · RHSA-2008:0787
Red Hat Enterprise Linux 2.1
kernel-0:2.4.9-e.74
Fixed · RHSA-2009:0001
Red Hat Enterprise Linux 3
kernel-0:2.4.21-57.EL
Fixed · RHSA-2008:0211
Red Hat Enterprise Linux 4
kernel-0:2.6.9-67.0.15.EL
Fixed · RHSA-2008:0237
Red Hat Enterprise Linux 5
kernel-0:2.6.18-53.1.19.el5
Fixed · RHSA-2008:0233
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | kernel-0:2.4.18-e.67 | Fixed | RHSA-2008:0787 |
| Red Hat Enterprise Linux 2.1 | kernel-0:2.4.9-e.74 | Fixed | RHSA-2009:0001 |
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-57.EL | Fixed | RHSA-2008:0211 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-67.0.15.EL | Fixed | RHSA-2008:0237 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-53.1.19.el5 | Fixed | RHSA-2008:0233 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (41)
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.vmware.com/pipermail/security-announce/2008/000023.html mailing-listx_refsource_MLIST
- http://lkml.org/lkml/2008/2/6/457 mailing-listx_refsource_MLISTExploit
- http://secunia.com/advisories/28806 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28826 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29058 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29570 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30018 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30110 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30112 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30116 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30769 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31246 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33280 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1019357 vdb-entryx_refsource_SECTRACK
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048 x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1503 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1504 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1565 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17 x_refsource_CONFIRMExploit
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:044 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:072 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:112 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:174 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0211.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0233.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0237.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0787.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/487808/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/27686 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/27705 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-618-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2008/0445/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2222/references vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-0007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=428961 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2008-0007
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9412 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-0007
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 8, 2008
Updated Aug 7, 2024
Reserved Dec 3, 2007
Link CVE-2008-0007
CISA Vulnrichment
Updated n/a