PoC Index

CVE-2008-0600

HIGH 7.2EPSS 3.5%

The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010.

CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
3.54% chance of exploitation in the next 30 days, 88th percentile
Published
2008-02-12
Updated
2024-08-07

Proof-of-concept exploits (5)

ExploitDB entries (2)

Exploit collections (1)

References

Related