CVE-2008-3535

NameCVE-2008-3535
DescriptionOff-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1636-1
NVD severitymedium (attack range: local)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linux-2.6source(unstable)2.6.26-2medium
linux-2.6sourceetch(not affected)
linux-2.6.24source(unstable)2.6.24-6~etchnhalf.5medium
linux-2.6.24sourceetch2.6.24-6~etchnhalf.5mediumDSA-1636-1

Notes

[etch] - linux-2.6 <not-affected> (Vulnerable code not present)
94ad374a0751f40d25e22e036c37f7263569d24c
Fixed in 2.6.25.14 and 2.6.26.1

Search for package or bug name: Reporting problems