CVE-2008-2365

Linux Kernel - Race Condition

Title source: rule

Description

Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Alexei Dobryanov · cdoslinux
https://www.exploit-db.com/exploits/31966
exploitdb WORKING POC VERIFIED
by Alexei Dobryanov · cdoslinux
https://www.exploit-db.com/exploits/31965

Scores

EPSS 0.0070
EPSS Percentile 71.8%

Classification

CWE
CWE-362
Status draft

Affected Products (50)

linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Jun 30, 2008
Tracked Since Feb 18, 2026