CVE-2008-3077

NameCVE-2008-3077
Descriptionarch/x86/kernel/ptrace.c in the Linux kernel before 2.6.25.10 on the x86_64 platform leaks task_struct references into the sys32_ptrace function, which allows local users to cause a denial of service (system crash) or have unspecified other impact via unknown vectors, possibly a use-after-free vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linux-2.6sourceetch(not affected)
linux-2.6source(unstable)2.6.25-7
linux-2.6.24source(unstable)(not affected)

Notes

- linux-2.6.24 <not-affected> (Vulnerable code added later)
[etch] - linux-2.6 <not-affected> (Vulnerable code added later)
1e9a615bfce7996ea4d815d45d364b47ac6a74e8

Search for package or bug name: Reporting problems