VYPR
Unrated severityNVD Advisory· Published Jun 10, 2008· Updated Jun 16, 2026

CVE-2008-2358

CVE-2008-2358

Description

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Linux/Kernel4 versions
    cpe:2.3:o:linux:linux_kernel:2.6.17:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:linux:linux_kernel:2.6.17:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.19:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.20:*:*:*:*:*:*:*
  • Range: 2.6.18, 2.6.17 - 2.6.20

Patches

Vulnerability mechanics

References

17

News mentions

0

No linked articles in our index yet.