|Description||The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.|
|Source||CVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|NVD severity||low (attack range: local)|
The information below is based on the following data on fixed versions.
- kernel-source-2.4.27 <not-affected> (Fixed before upload in the archive; 2.4.22-pre4)