Description
Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.
References (7)
Core 7
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2004/dsa-423
Patch, Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-025.html
Vendor Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/11249.php
Various Sources vendor-advisory
x_refsource_mandrake
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014
Various Sources x_refsource_confirm
http://linux.bkbits.net:8080/linux-2.4/cset%403e2f193drGJDBg9SG6JwaDQwCBnAMQ
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6763
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2003/dsa-358
Scores
EPSS
0.0037
EPSS Percentile
29.9%
Details
Status
published
Products (10)
linux/linux_kernel
2.4.10
linux/linux_kernel
2.4.11
linux/linux_kernel
2.4.12
linux/linux_kernel
2.4.13
linux/linux_kernel
2.4.14
linux/linux_kernel
2.4.15
linux/linux_kernel
2.4.16
linux/linux_kernel
2.4.17
linux/linux_kernel
2.4.18
linux/linux_kernel
2.4.19
Published
Feb 19, 2003
Tracked Since
Feb 18, 2026