CVE-2008-3915
published 2008-09-11CVE-2008-3915: Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to…
PriorityP345critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.35%
90.1th percentile
Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6x74-h8w8-x4pj: Buffer overflow in nfsd in the Linux kernel before 2
ghsa_unreviewed·2022-05-02
CVE-2008-3915 [HIGH] CWE-119 GHSA-6x74-h8w8-x4pj: Buffer overflow in nfsd in the Linux kernel before 2
Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-10-27·CVSS 5.5
CVE-2007-6716 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the direct-IO subsystem did not correctly validate
certain structures. A local attacker could exploit this to cause a system
crash, leading to a denial of service. (CVE-2007-6716)
It was discovered that the disabling of the ZERO_PAGE optimization could
lead to large memory consumption. A local attacker could exploit this to
allocate all available memory, leading to a denial of service.
(CVE-2008-2372)
It was discovered that the Datagram Congestion Control Protocol (DCCP) did
not correctly validate its arguments. If DCCP was in use, a remote attacker
could send specially crafted network traffic and cause a system crash,
leading to a denial of service. (CVE-2008-3276)
It was discovered that
Red Hat
kernel: nfsd: fix buffer overrun decoding NFSv4 acl
vendor_redhat·2008-09-01·CVSS 9.3
CVE-2008-3915 [CRITICAL] kernel: nfsd: fix buffer overrun decoding NFSv4 acl
kernel: nfsd: fix buffer overrun decoding NFSv4 acl
Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=91b80969ba466ba4b915a4a1d03add8c297add3fhttp://lkml.org/lkml/2008/9/3/286http://secunia.com/advisories/31881http://secunia.com/advisories/32190http://secunia.com/advisories/32393http://www.debian.org/security/2008/dsa-1636http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.4http://www.openwall.com/lists/oss-security/2008/09/04/18http://www.openwall.com/lists/oss-security/2008/09/04/4http://www.redhat.com/support/errata/RHSA-2008-0857.htmlhttp://www.securityfocus.com/bid/31133http://www.ubuntu.com/usn/usn-659-1https://bugzilla.redhat.com/show_bug.cgi?id=461101https://exchange.xforce.ibmcloud.com/vulnerabilities/45055http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=91b80969ba466ba4b915a4a1d03add8c297add3fhttp://lkml.org/lkml/2008/9/3/286http://secunia.com/advisories/31881http://secunia.com/advisories/32190http://secunia.com/advisories/32393http://www.debian.org/security/2008/dsa-1636http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.4http://www.openwall.com/lists/oss-security/2008/09/04/18http://www.openwall.com/lists/oss-security/2008/09/04/4http://www.redhat.com/support/errata/RHSA-2008-0857.htmlhttp://www.securityfocus.com/bid/31133http://www.ubuntu.com/usn/usn-659-1https://bugzilla.redhat.com/show_bug.cgi?id=461101https://exchange.xforce.ibmcloud.com/vulnerabilities/45055
2008-09-11
Published