kernel: add rcu_read_lock() to fcheck() in both dnotify, locks.c and fix fcntl store/load race in locks.c
Published May 8, 2008
6.9
MEDIUMCVSS 2.0
EPSS 0.41%
Description
Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain "re-ordered access to the descriptor table."
Affected products
No data.
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.1
- 2.6.1
- 2.6.1
- 2.6.1
- 2.6.2
- 2.6.2
- 2.6.2
- 2.6.2
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.4
- 2.6.4
- 2.6.4
- 2.6.4
- 2.6.5
- 2.6.5
- 2.6.5
- 2.6.5
- 2.6.6
- 2.6.6
- 2.6.6
- 2.6.6
- 2.6.7
- 2.6.7
- 2.6.7
- 2.6.7
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8.1
- 2.6.8.1.5
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.10
- 2.6.10
- 2.6.10
- 2.6.10
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.11_rc1_bk6
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.12.12
- 2.6.12.22
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.15.11
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.16.24
- 2.6.16.25
- 2.6.16.26
- 2.6.16.27
- 2.6.16.28
- 2.6.16.29
- 2.6.16.30
- 2.6.16.31
- 2.6.16.32
- 2.6.16.33
- 2.6.16.34
- 2.6.16.35
- 2.6.16.36
- 2.6.16.37
- 2.6.16.38
- 2.6.16.39
- 2.6.16.40
- 2.6.16.41
- 2.6.16.43
- 2.6.16.44
- 2.6.16.45
- 2.6.16.46
- 2.6.16.47
- 2.6.16.48
- 2.6.16.49
- 2.6.16.50
- 2.6.16.51
- 2.6.16.52
- 2.6.16.53
- 2.6.16_rc7
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
- 2.6.17.4
- 2.6.17.5
- 2.6.17.6
- 2.6.17.7
- 2.6.17.8
- 2.6.17.9
- 2.6.17.10
- 2.6.17.11
- 2.6.17.12
- 2.6.17.13
- 2.6.17.14
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18.1
- 2.6.18.2
- 2.6.18.3
- 2.6.18.4
- 2.6.18.5
- 2.6.18.6
- 2.6.18.7
- 2.6.18.8
- 2.6.19
- 2.6.19
- 2.6.19
- 2.6.19
- 2.6.19
- 2.6.19.1
- 2.6.19.2
- 2.6.19.3
- 2.6.20
- 2.6.20
- 2.6.20.1
- 2.6.20.2
- 2.6.20.3
- 2.6.20.4
- 2.6.20.5
- 2.6.20.6
- 2.6.20.7
- 2.6.20.8
- 2.6.20.9
- 2.6.20.10
- 2.6.20.11
- 2.6.20.12
- 2.6.20.13
- 2.6.20.14
- 2.6.20.15
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21
- 2.6.21.1
- 2.6.21.2
- 2.6.21.3
- 2.6.21.4
- 2.6.22
- 2.6.22
- 2.6.22.1
- 2.6.22.3
- 2.6.22.4
- 2.6.22.5
- 2.6.22.6
- 2.6.22.7
- 2.6.22.16
- 2.6.23
- 2.6.23
- 2.6.23
- 2.6.23.1
- 2.6.23.2
- 2.6.23.3
- 2.6.23.4
- 2.6.23.5
- 2.6.23.6
- 2.6.23.7
- 2.6.23.9
- 2.6.23.14
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24.1
- 2.6.24.2
- 2.6.24.3
- 2.6.24.4
- 2.6.24.5
- 2.6.25
- 2.6.25.1
- 2.6_test9_cvs
No data.
Red Hat Enterprise Linux 3
kernel-0:2.4.21-57.EL
Fixed · RHSA-2008:0211
Red Hat Enterprise Linux 4
kernel-0:2.6.9-67.0.15.EL
Fixed · RHSA-2008:0237
Red Hat Enterprise Linux 5
kernel-0:2.6.18-53.1.19.el5
Fixed · RHSA-2008:0233
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-57.EL | Fixed | RHSA-2008:0211 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-67.0.15.EL | Fixed | RHSA-2008:0237 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-53.1.19.el5 | Fixed | RHSA-2008:0233 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.41% (0.00411) | 32.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.41% (0.00406) | 32.07th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.11% (0.00114) | 27.56th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.05% (0.03054) | 83.72th | v2 (v2022.01.01) |
| Feb 13, 2023 | 3.05% (0.03054) | 83.28th | v2 (v2022.01.01) |
| Feb 3, 2023 | 4.42% (0.04421) | 87.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.05% (0.03054) | 82.05th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.05% (0.03054) | 64.53th | v2 (v2022.01.01) |
References (49)
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00012.html vendor-advisoryx_refsource_SUSE
- http://lists.vmware.com/pipermail/security-announce/2008/000023.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/30077 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30101 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30108 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30110 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30112 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30116 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30164 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30252 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30260 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30276 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30515 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30769 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30818 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30962 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30982 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31246 third-party-advisoryx_refsource_SECUNIA
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0162 x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1575 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.4 x_refsource_CONFIRM
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.2 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:104 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:105 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:167 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0211.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0233.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0237.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/491740/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/29076 vdb-entryx_refsource_BIDPatch
- http://www.securitytracker.com/id?1019974 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-618-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2008/1451/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1452/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2222/references vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-1669 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=443433 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42242 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-2518 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2008-1669
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10065 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/614-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2008-1669
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00232.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00294.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00357.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.