CVE-2008-4934
published 2008-11-05CVE-2008-4934: The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the…
PriorityP430high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.29%
87.3th percentile
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.28 | 2.6.28 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.8HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-11-27·CVSS 4.9
CVE-2007-5498 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the Xen hypervisor block driver did not correctly
validate requests. A user with root privileges in a guest OS could make a
malicious IO request with a large number of blocks that would crash the
host OS, leading to a denial of service. This only affected Ubuntu 7.10.
(CVE-2007-5498)
It was discovered the the i915 video driver did not correctly validate
memory addresses. A local attacker could exploit this to remap memory that
could cause a system crash, leading to a denial of service. This issue did
not affect Ubuntu 6.06 and was previous fixed for Ubuntu 7.10 and 8.04 in
USN-659-1. Ubuntu 8.10 has now been corrected as well. (CVE-2008-3831)
David Watson discovered that the kernel did not
Red Hat
kernel: hfsplus: check read_mapping_page() return value
vendor_redhat·2008-10-15·CVSS 7.8
CVE-2008-4934 [HIGH] kernel: hfsplus: check read_mapping_page() return value
kernel: hfsplus: check read_mapping_page() return value
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
GHSA
GHSA-5hf7-wh5w-w87p: The hfsplus_block_allocate function in fs/hfsplus/bitmap
ghsa_unreviewed·2022-05-14
CVE-2008-4934 [HIGH] CWE-20 GHSA-5hf7-wh5w-w87p: The hfsplus_block_allocate function in fs/hfsplus/bitmap
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=649f1ee6c705aab644035a7998d7b574193a598ahttp://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1http://rhn.redhat.com/errata/RHSA-2009-0264.htmlhttp://secunia.com/advisories/32510http://secunia.com/advisories/32918http://secunia.com/advisories/32998http://secunia.com/advisories/33180http://secunia.com/advisories/33556http://secunia.com/advisories/33858http://www.debian.org/security/2008/dsa-1681http://www.debian.org/security/2008/dsa-1687http://www.mandriva.com/security/advisories?name=MDVSA-2008:234http://www.openwall.com/lists/oss-security/2008/11/03/2http://www.redhat.com/support/errata/RHSA-2009-0014.htmlhttp://www.securityfocus.com/bid/32096http://www.ubuntu.com/usn/usn-679-1https://exchange.xforce.ibmcloud.com/vulnerabilities/46327https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11635http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=649f1ee6c705aab644035a7998d7b574193a598ahttp://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1http://rhn.redhat.com/errata/RHSA-2009-0264.htmlhttp://secunia.com/advisories/32510http://secunia.com/advisories/32918http://secunia.com/advisories/32998http://secunia.com/advisories/33180http://secunia.com/advisories/33556http://secunia.com/advisories/33858http://www.debian.org/security/2008/dsa-1681http://www.debian.org/security/2008/dsa-1687http://www.mandriva.com/security/advisories?name=MDVSA-2008:234http://www.openwall.com/lists/oss-security/2008/11/03/2http://www.redhat.com/support/errata/RHSA-2009-0014.htmlhttp://www.securityfocus.com/bid/32096http://www.ubuntu.com/usn/usn-679-1https://exchange.xforce.ibmcloud.com/vulnerabilities/46327https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11635
2008-11-05
Published