CVE-2008-1294
Summary
| CVE | CVE-2008-1294 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-05-02 16:05:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:N/I:N/A:P
Problem Types: CWE-20 | CWE-399 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:L/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.20 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.21 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.22 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.23 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.24 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.25 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.26 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.27 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.28 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.29 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.30 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.31 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.32 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.33 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.34 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.35 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.36 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.37 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.38 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.39 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.40 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.41 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.43 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.44 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.45 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.46 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.47 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.48 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.49 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.50 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.51 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.52 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.53 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16_rc7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc7 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.2 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.2 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.2 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | git1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | git2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | git3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | git4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | git5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | git6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | git7 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21.4 | All | All | All |
| Operating System | Linux | Linux Kernel | All | rc7 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-1565-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 215000 – Kernel <2.6.22 RLIMIT_CPU could be avoided (CVE-2008-1294) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Ubuntu update for kernel - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Red Hat update for kernel - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| USN-618-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Debian update for kernel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Linux Kernel RLIMIT_CPU Zero Limit Handling Local Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-01-15 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2008-0612.html |
Legacy QID Mappings
- 591311 Bosch Rexroth PRA-ES8P2S Ethernet-Switch Multiple Vulnerabilities (BOSCH-SA-247053-BT)