Buffer overflow in the (1) sysfs_show_available_clocksources and (2) sysfs_show_current_clocksources functions in Linux kernel 2.6.23 and earlier might allow local users to cause a denial of service or execute arbitrary code via crafted clock source names. NOTE: follow-on analysis by Linux developers states that "There is no way for unprivileged users (or really even the root user) to add new clocksources.
History

No history.

cve-icon MITRE

Status: REJECTED

Assigner: mitre

Published: 2007-11-09T19:00:00

Updated: 2007-11-28T10:00:00

Reserved: 2007-11-09T00:00:00

Link: CVE-2007-5908

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2007-11-09T19:46:00.000

Modified: 2023-11-07T02:01:24.240

Link: CVE-2007-5908

cve-icon Redhat

Severity : Important

Publid Date: 2007-11-08T00:00:00Z

Links: CVE-2007-5908 - Bugzilla