Vulnerability Description
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 2.6.25.15 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Suse | Suse Linux Enterprise Desktop | 10 |
| Suse | Suse Linux Enterprise Server | 10 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.15Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00001.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.htmlMailing ListThird Party Advisory
- http://lkml.org/lkml/2008/7/2/83ExploitMailing ListThird Party Advisory
- http://secunia.com/advisories/31551Broken Link
- http://secunia.com/advisories/31614Broken Link
- http://secunia.com/advisories/31836Broken Link
- http://secunia.com/advisories/31881Broken Link
- http://secunia.com/advisories/32023Broken Link
- http://secunia.com/advisories/32104Broken Link
- http://secunia.com/advisories/32190Broken Link
- http://secunia.com/advisories/32344Broken Link
- http://secunia.com/advisories/33201Broken Link
- http://secunia.com/advisories/33280Broken Link
FAQ
What is CVE-2008-3275?
CVE-2008-3275 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) di...
How severe is CVE-2008-3275?
CVE-2008-3275 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3275?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux, Canonical Ubuntu Linux, Suse Suse Linux Enterprise Desktop, Suse Suse Linux Enterprise Server.