Description
The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1681-1 | New Linux 2.6.24 packages fix several vulnerabilities |
Debian DSA |
DSA-1687-1 | New Linux 2.6.18 packages fix several vulnerabilities |
EUVD |
EUVD-2008-4535 | The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file. |
Ubuntu USN |
USN-679-1 | Linux kernel vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T10:17:09.869Z
Reserved: 2008-10-14T00:00:00.000Z
Link: CVE-2008-4554
No data.
Status : Deferred
Published: 2008-10-15T20:07:42.763
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4554
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN