CVE-2008-0009
Linux kernel <2.6.25 - Memory Corruption
Title source: llmDescription
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.
Exploits (2)
References (11)
Scores
EPSS
0.0094
EPSS Percentile
76.0%
Classification
CWE
CWE-20
Status
draft
Affected Products (23)
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 8 more
Timeline
Published
Feb 12, 2008
Tracked Since
Feb 18, 2026