CVE-2008-5029
MEDIUM 4.9EPSS 0.5%
The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.
- CVSS v2.0
- 4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C - EPSS
- 0.50% chance of exploitation in the next 30 days, 41th percentile
- Published
- 2008-11-10
- Updated
- 2024-08-07
Proof-of-concept exploits (3)
- http://www.securityfocus.com/archive/1/499744/100/0/threaded
- http://www.securityfocus.com/archive/1/499700/100/0/threaded
- http://archives.neohapsis.com/archives/bugtraq/2009-01/0006.html