CVE-2008-2372

Linux Kernel - Improper Input Validation

Title source: rule

Description

The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly zeroed pages."

References (20)

Scores

EPSS 0.0005
EPSS Percentile 14.5%

Classification

CWE
CWE-20
Status draft

Affected Products (10)

linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel

Timeline

Published Jul 02, 2008
Tracked Since Feb 18, 2026