CVE-2008-4302

fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-09-29 17:17

Updated : 2024-02-15 20:24


NVD link : CVE-2008-4302

Mitre link : CVE-2008-4302

CVE.ORG link : CVE-2008-4302


JSON object : View

Products Affected

redhat

  • enterprise_linux

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-667

Improper Locking