CVE-2008-3275

MEDIUM

Linux kernel <2.6.25.15 - DoS

Title source: llm

Description

The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.

Scores

CVSS v3 5.5
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-120
Status draft

Affected Products (8)

linux/linux_kernel < 2.6.25.15
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
suse/suse_linux_enterprise_desktop
suse/suse_linux_enterprise_server

Timeline

Published Aug 12, 2008
Tracked Since Feb 18, 2026