// For flags

CVE-2008-3527

kernel: missing boundary checks in syscall/syscall32_nopage()

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions.

arch/i386/kernel/sysenter.c en la implementación Virtual Dynamic Shared Objects (vDSO) para el kernel de Linux anterior a v2.6.21, no comprueba de forma adecuada los límites; esto permite a usuarios locales ganar privilegios o provocar una denegación de servicio a través de vectores no especificados. Está relacionado con las funciones install_special_mapping, syscall y syscall32_nopage.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-08-07 CVE Reserved
  • 2008-11-05 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
<= 2.6.20.21
Search vendor "Linux" for product "Linux Kernel" and version " <= 2.6.20.21"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.2.27
Search vendor "Linux" for product "Linux Kernel" and version "2.2.27"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.4.36
Search vendor "Linux" for product "Linux Kernel" and version "2.4.36"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.4.36.1
Search vendor "Linux" for product "Linux Kernel" and version "2.4.36.1"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.4.36.2
Search vendor "Linux" for product "Linux Kernel" and version "2.4.36.2"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.4.36.3
Search vendor "Linux" for product "Linux Kernel" and version "2.4.36.3"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.4.36.4
Search vendor "Linux" for product "Linux Kernel" and version "2.4.36.4"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.4.36.5
Search vendor "Linux" for product "Linux Kernel" and version "2.4.36.5"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.4.36.6
Search vendor "Linux" for product "Linux Kernel" and version "2.4.36.6"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6
Search vendor "Linux" for product "Linux Kernel" and version "2.6"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
rc1
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
rc2
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
rc3
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
rc4
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
rc5
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
rc6
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.18"
rc7
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.19.4
Search vendor "Linux" for product "Linux Kernel" and version "2.6.19.4"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.19.5
Search vendor "Linux" for product "Linux Kernel" and version "2.6.19.5"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.19.6
Search vendor "Linux" for product "Linux Kernel" and version "2.6.19.6"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.19.7
Search vendor "Linux" for product "Linux Kernel" and version "2.6.19.7"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.20.16
Search vendor "Linux" for product "Linux Kernel" and version "2.6.20.16"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.20.17
Search vendor "Linux" for product "Linux Kernel" and version "2.6.20.17"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.20.18
Search vendor "Linux" for product "Linux Kernel" and version "2.6.20.18"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.20.19
Search vendor "Linux" for product "Linux Kernel" and version "2.6.20.19"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.20.20
Search vendor "Linux" for product "Linux Kernel" and version "2.6.20.20"
-
Affected