CVE-2008-2812
published 2008-07-09CVE-2008-2812: The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly…
PriorityP428high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
34.7th percentile
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | communication_manager | >= 3.1 | — |
| avaya | intuity_audix_lx | — | — |
| avaya | meeting_exchange | — | — |
| avaya | message_networking | — | — |
| avaya | messaging_storage_server | — | — |
| avaya | proactive_contact | — | — |
| avaya | sip_enablement_services | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.25.10 | 2.6.25.10 |
| novell | linux_desktop | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | suse_linux_enterprise_desktop | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.8HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-08-25·CVSS 4.9
CVE-2008-3272 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that there were multiple NULL-pointer function
dereferences in the Linux kernel terminal handling code. A local attacker
could exploit this to execute arbitrary code as root, or crash the system,
leading to a denial of service. (CVE-2008-2812)
The do_change_type routine did not correctly validation administrative
users. A local attacker could exploit this to block mount points or cause
private mounts to be shared, leading to denial of service or a possible
loss of privacy. (CVE-2008-2931)
Tobias Klein discovered that the OSS interface through ALSA did not
correctly validate the device number. A local attacker could exploit this
to access sensitive kernel memory, leading to a denial of service or
Red Hat
kernel: NULL ptr dereference in multiple network drivers due to missing checks in tty code
vendor_redhat·2008-04-30·CVSS 7.8
CVE-2008-2812 [HIGH] kernel: NULL ptr dereference in multiple network drivers due to missing checks in tty code
kernel: NULL ptr dereference in multiple network drivers due to missing checks in tty code
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
GHSA
GHSA-g469-pq25-x2qr: The Linux kernel before 2
ghsa_unreviewed·2022-05-01
CVE-2008-2812 [HIGH] CWE-476 GHSA-g469-pq25-x2qr: The Linux kernel before 2
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.25.y.git%3Ba=commitdiff%3Bh=2a739dd53ad7ee010ae6e155438507f329dce788http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.10http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://secunia.com/advisories/30982http://secunia.com/advisories/31048http://secunia.com/advisories/31202http://secunia.com/advisories/31229http://secunia.com/advisories/31341http://secunia.com/advisories/31551http://secunia.com/advisories/31614http://secunia.com/advisories/31685http://secunia.com/advisories/32103http://secunia.com/advisories/32370http://secunia.com/advisories/32759http://secunia.com/advisories/33201http://support.avaya.com/elmodocs2/security/ASA-2008-365.htmhttp://www.debian.org/security/2008/dsa-1630http://www.openwall.com/lists/oss-security/2008/07/03/2http://www.redhat.com/support/errata/RHSA-2008-0612.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0665.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0973.htmlhttp://www.securityfocus.com/bid/30076http://www.vupen.com/english/advisories/2008/2063/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43687https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11632https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6633https://usn.ubuntu.com/637-1/http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.25.y.git%3Ba=commitdiff%3Bh=2a739dd53ad7ee010ae6e155438507f329dce788http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.10http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://secunia.com/advisories/30982http://secunia.com/advisories/31048http://secunia.com/advisories/31202http://secunia.com/advisories/31229http://secunia.com/advisories/31341http://secunia.com/advisories/31551http://secunia.com/advisories/31614http://secunia.com/advisories/31685http://secunia.com/advisories/32103http://secunia.com/advisories/32370http://secunia.com/advisories/32759http://secunia.com/advisories/33201http://support.avaya.com/elmodocs2/security/ASA-2008-365.htmhttp://www.debian.org/security/2008/dsa-1630http://www.openwall.com/lists/oss-security/2008/07/03/2http://www.redhat.com/support/errata/RHSA-2008-0612.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0665.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0973.htmlhttp://www.securityfocus.com/bid/30076http://www.vupen.com/english/advisories/2008/2063/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43687https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11632https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6633https://usn.ubuntu.com/637-1/
2008-07-09
Published