CVE-2008-4302
MEDIUMLinux Kernel < 2.6.22.2 - Denial of Service via Splice Subsystem Page Unlock
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4302. PoCs published by Jens Axboe.
AI-analyzed exploit summary This exploit is a configuration file for the fio tool designed to trigger a local denial-of-service vulnerability in the Linux kernel prior to version 2.6.22.2 by stressing the I/O subsystem with multiple jobs and high I/O depth.
Description
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.
Exploits (1)
This exploit is a configuration file for the fio tool designed to trigger a local denial-of-service vulnerability in the Linux kernel prior to version 2.6.22.2 by stressing the I/O subsystem with multiple jobs and high I/O depth.
References (15)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H