CVE-2008-0600 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 3.5% (pctl 89)
Patch early
A public exploit exists.
Description
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 3.54% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-02-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| linux | linux kernel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2) | 2008-02-09 |
| exploit-db | Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1) | 2008-02-09 |
References
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html
- http://marc.info/?l=linux-kernel&m=120263652322197&w=2
- http://marc.info/?l=linux-kernel&m=120264520431307&w=2
- http://marc.info/?l=linux-kernel&m=120264773202422&w=2
- http://marc.info/?l=linux-kernel&m=120266328220808&w=2
- http://marc.info/?l=linux-kernel&m=120266353621139&w=2
- http://secunia.com/advisories/28835
- http://secunia.com/advisories/28858
- http://secunia.com/advisories/28875
- http://secunia.com/advisories/28889
- http://secunia.com/advisories/28896
- http://secunia.com/advisories/28912
- http://secunia.com/advisories/28925
- http://secunia.com/advisories/28933
- http://secunia.com/advisories/28937
- http://secunia.com/advisories/29245
- http://secunia.com/advisories/30818
- http://securitytracker.com/id?1019393
→ the Explorer · watch your stack · NVD