CVE-2008-2358

Linux Kernel - Numeric Error

Title source: rule

Description

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.

Scores

EPSS 0.0007
EPSS Percentile 20.1%

Classification

CWE
CWE-189
Status draft

Affected Products (4)

linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel

Timeline

Published Jun 10, 2008
Tracked Since Feb 18, 2026