Unrated severityNVD Advisory· Published Feb 12, 2008· Updated Apr 23, 2026
CVE-2008-0010
CVE-2008-0010
Description
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.
Affected products
23cpe:2.3:o:linux:linux_kernel:2.6.22:*:*:*:*:*:*:*+ 22 more
- cpe:2.3:o:linux:linux_kernel:2.6.22:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22.1:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22.16:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22.3:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22.4:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22.5:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22.6:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22.7:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.22:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.1:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.14:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.2:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.3:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.4:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.5:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.6:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.7:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23.9:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.23:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.24:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.24:rc3:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txtnvdExploit
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1nvdExploit
- secunia.com/advisories/28835nvd
- secunia.com/advisories/28875nvd
- secunia.com/advisories/28896nvd
- www.debian.org/security/2008/dsa-1494nvd
- www.securityfocus.com/archive/1/487982/100/0/threadednvd
- www.securityfocus.com/bid/27704nvd
- www.securityfocus.com/bid/27796nvd
- www.vupen.com/english/advisories/2008/0487/referencesnvd
- www.exploit-db.com/exploits/5093nvd
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.htmlnvd
News mentions
0No linked articles in our index yet.