CVE-2008-3534
published 2008-08-08CVE-2008-3534: The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.53%
42.0th percentile
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as demonstrated by the insserv program, related to allocation of "useless pages" and improper maintenance of the i_blocks count.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.26.1 | 2.6.26.1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_ubuntu5.5MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-10-27·CVSS 5.5
CVE-2007-6716 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the direct-IO subsystem did not correctly validate
certain structures. A local attacker could exploit this to cause a system
crash, leading to a denial of service. (CVE-2007-6716)
It was discovered that the disabling of the ZERO_PAGE optimization could
lead to large memory consumption. A local attacker could exploit this to
allocate all available memory, leading to a denial of service.
(CVE-2008-2372)
It was discovered that the Datagram Congestion Control Protocol (DCCP) did
not correctly validate its arguments. If DCCP was in use, a remote attacker
could send specially crafted network traffic and cause a system crash,
leading to a denial of service. (CVE-2008-3276)
It was discovered that
Red Hat
kernel: tmpfs: fix kernel BUG in shmem_delete_inode
vendor_redhat·2008-07-26·CVSS 4.9
CVE-2008-3534 [MEDIUM] kernel: tmpfs: fix kernel BUG in shmem_delete_inode
kernel: tmpfs: fix kernel BUG in shmem_delete_inode
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as demonstrated by the insserv program, related to allocation of "useless pages" and improper maintenance of the i_blocks count.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5.
GHSA
GHSA-g59v-xw9p-fc4r: The shmem_delete_inode function in mm/shmem
ghsa_unreviewed·2022-05-02
CVE-2008-3534 [MEDIUM] CWE-400 GHSA-g59v-xw9p-fc4r: The shmem_delete_inode function in mm/shmem
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as demonstrated by the insserv program, related to allocation of "useless pages" and improper maintenance of the i_blocks count.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=14fcc23fdc78e9d32372553ccf21758a9bd56fa1http://lkml.org/lkml/2008/7/26/71http://secunia.com/advisories/31881http://secunia.com/advisories/32190http://secunia.com/advisories/32393http://www.debian.org/security/2008/dsa-1636http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.1http://www.redhat.com/support/errata/RHSA-2008-0857.htmlhttp://www.securityfocus.com/bid/31134http://www.ubuntu.com/usn/usn-659-1https://exchange.xforce.ibmcloud.com/vulnerabilities/44489http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=14fcc23fdc78e9d32372553ccf21758a9bd56fa1http://lkml.org/lkml/2008/7/26/71http://secunia.com/advisories/31881http://secunia.com/advisories/32190http://secunia.com/advisories/32393http://www.debian.org/security/2008/dsa-1636http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.1http://www.redhat.com/support/errata/RHSA-2008-0857.htmlhttp://www.securityfocus.com/bid/31134http://www.ubuntu.com/usn/usn-659-1https://exchange.xforce.ibmcloud.com/vulnerabilities/44489
2008-08-08
Published