CVE-2008-0009

Linux kernel <2.6.25 - Memory Corruption

Title source: llm

Description

The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.

Exploits (2)

exploitdb WORKING POC
clocallinux
https://www.exploit-db.com/exploits/5093
exploitdb WORKING POC
clocallinux
https://www.exploit-db.com/exploits/5092

Scores

EPSS 0.0094
EPSS Percentile 76.4%

Details

CWE
CWE-20
Status published
Products (19)
linux/linux_kernel 2.6.22 (2 CPE variants)
linux/linux_kernel 2.6.22.1
linux/linux_kernel 2.6.22.3
linux/linux_kernel 2.6.22.4
linux/linux_kernel 2.6.22.5
linux/linux_kernel 2.6.22.6
linux/linux_kernel 2.6.22.7
linux/linux_kernel 2.6.22.16
linux/linux_kernel 2.6.23 (3 CPE variants)
linux/linux_kernel 2.6.23.1
... and 9 more
Published Feb 12, 2008
Tracked Since Feb 18, 2026