CVE-2008-0010

Linux kernel <2.6.25 - Info Disclosure

Title source: llm

Description

The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.

Exploits (2)

exploitdb WORKING POC VERIFIED
by qaaz · clocallinux
https://www.exploit-db.com/exploits/5093
exploitdb WORKING POC
clocallinux
https://www.exploit-db.com/exploits/5092

Scores

EPSS 0.0022
EPSS Percentile 44.9%

Classification

CWE
CWE-20
Status draft

Affected Products (23)

linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 8 more

Timeline

Published Feb 12, 2008
Tracked Since Feb 18, 2026