Buffer overflow in the (1) sysfs_show_available_clocksources and (2) sysfs_show_current_clocksources functions in Linux kernel 2.6.23 and earlier might allow local users to cause a denial of service or execute arbitrary code via crafted clock source names. NOTE: follow-on analysis by Linux developers states that "There is no way for unprivileged users (or really even the root user) to add new clocksources.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.cve.org/CVERecord?id=CVE-2007-5908 |
|
History
Wed, 28 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: mitre
Published:
Updated: 2007-11-28T15:00:00.000Z
Reserved: 2007-11-09T05:00:00.000Z
Link: CVE-2007-5908
No data.
Status : Rejected
Published: 2007-11-09T19:46:00.000
Modified: 2023-11-07T02:01:24.240
Link: CVE-2007-5908
OpenCVE Enrichment
No data.
Weaknesses
No weakness.