CVE-2008-4554

Linux Kernel < 2.6.27 - Arbitrary File Write via O_APPEND Flag Bypass

Title source: llm
STIX 2.1

Description

The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file.

References (24)

Core 24
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35390
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32998
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/10/13/1
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=466707
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:224
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11142
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45954
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31903
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0009.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/10/14/5
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33586
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1687
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32918
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-679-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33180
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-1017.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32386
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1681
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33182

Scores

EPSS 0.0039
EPSS Percentile 32.1%

Details

CWE
CWE-264
Status published
Products (43)
linux/linux_kernel 2.2.27
linux/linux_kernel 2.4.36
linux/linux_kernel 2.4.36.1
linux/linux_kernel 2.4.36.2
linux/linux_kernel 2.4.36.3
linux/linux_kernel 2.4.36.4
linux/linux_kernel 2.4.36.5
linux/linux_kernel 2.4.36.6
linux/linux_kernel 2.6
linux/linux_kernel 2.6.18 (8 CPE variants)
... and 33 more
Published Oct 15, 2008
Tracked Since Feb 18, 2026