Local Privilege Escalation in Linux Kernel Versions by Vendor
CVE-2008-0600

Currently unrated

Key Information:

Vendor

Linux

Vendor
CVE Published:
12 February 2008

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2008-0600?

The vmsplice_to_pipe function in the Linux kernel versions 2.6.17 through 2.6.24.1 contains a flaw where it fails to properly validate certain userspace pointers before dereferencing them. This oversight allows local users to exploit the functionality of the vmsplice system call by supplying crafted arguments, potentially enabling them to gain root privileges on the system. This vulnerability remains distinct from other reported issues and emphasizes the importance of pointer validation in maintaining system security.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.