CVE-2008-4302
MEDIUMLinux Kernel < 2.6.22.2 - Improper Locking
Title source: ruleDescription
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Jens Axboe · textdoslinux
https://www.exploit-db.com/exploits/32384
References (15)
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
36.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-667
Status
draft
Affected Products (3)
linux/linux_kernel
< 2.6.22.2
debian/debian_linux
redhat/enterprise_linux
Timeline
Published
Sep 29, 2008
Tracked Since
Feb 18, 2026