Kernel doesn't clear DF for signal handlers
Published Mar 17, 2008
7.5
HIGHCVSS 2.0
EPSS 2.79%
Description
gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
kernel-0:2.4.21-57.EL
Fixed · RHSA-2008:0211
Red Hat Enterprise Linux 4
kernel-0:2.6.9-67.0.20.EL
Fixed · RHSA-2008:0508
Red Hat Enterprise Linux 5
kernel-0:2.6.18-53.1.19.el5
Fixed · RHSA-2008:0233
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-57.EL | Fixed | RHSA-2008:0211 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-67.0.20.EL | Fixed | RHSA-2008:0508 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-53.1.19.el5 | Fixed | RHSA-2008:0233 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.79% (0.02791) | 85.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.79% (0.02791) | 84.51th | v5 (v2026.06.15) |
| Mar 30, 2025 | 3.40% (0.03396) | 86.27th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.64% (0.04642) | 81.78th | v4 (v2025.03.14) |
| Mar 19, 2025 | 3.40% (0.03396) | 85.98th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.19% (0.02189) | 83.23th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.58% (0.01578) | 87.82th | v3 (v2023.03.01) |
| Mar 23, 2024 | 1.50% (0.01497) | 86.59th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.54% (0.01535) | 85.01th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
References (31)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469058 x_refsource_CONFIRM
- http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00417.html mailing-listx_refsource_MLIST
- http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00428.html mailing-listx_refsource_MLIST
- http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00432.html mailing-listx_refsource_MLIST
- http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00499.html mailing-listx_refsource_MLIST
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e40cd10ccff3d9fbffd57b93780bee4b7b9bff51 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00000.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.vmware.com/pipermail/security-announce/2008/000023.html mailing-listx_refsource_MLIST
- http://lkml.org/lkml/2008/3/5/207 mailing-listx_refsource_MLISTExploit
- http://lwn.net/Articles/272048/#Comments x_refsource_MISC
- http://marc.info/?l=git-commits-head&m=120492000901739&w=2 mailing-listx_refsource_MLIST
- http://rhn.redhat.com/errata/RHSA-2008-0508.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/30110 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30116 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30818 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30850 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30890 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30962 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31246 third-party-advisoryx_refsource_SECUNIA
- http://www.redhat.com/support/errata/RHSA-2008-0211.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0233.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/29084 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2008/2222/references vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-1367 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=437312 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41340 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-1367
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11108 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-1367
Change history (0)
No recorded changes yet.