Security Advisory

CVE-2008-4302

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-09-29 17:00:00
Last updated 2024-08-07 10:08:35
Assigner mitre
State PUBLISHED

Description

fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.