CVE-2008-4210 EXPLOIT
4.6
MEDIUM · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
Scoring
| CVSS | 4.6 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.14% — more likely to be exploited than 81% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-09-29 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| linux | linux kernel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel < 2.6.22 - 'ftruncate()'/'open()' Local Privilege Escalation | 2008-10-27 |
References
- http://bugzilla.kernel.org/show_bug.cgi?id=8420
- http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=7b82dc0e64e93f430182f36b46b79fcee87d3532
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2008-0972.html
- http://secunia.com/advisories/32237
- http://secunia.com/advisories/32344
- http://secunia.com/advisories/32356
- http://secunia.com/advisories/32485
- http://secunia.com/advisories/32759
- http://secunia.com/advisories/32799
- http://secunia.com/advisories/32918
- http://secunia.com/advisories/33201
- http://secunia.com/advisories/33280
- http://www.debian.org/security/2008/dsa-1653
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:220
→ the Explorer · watch your stack · NVD