CVE-2008-3527
Summary
| CVE | CVE-2008-3527 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-05 15:00:14 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.2.27 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc7 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.20 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:025 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Linux Kernel Virtual Dynamic Shared Objects Boundary Error May Let Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red hat update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1687-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Bug 460251 – CVE-2008-3527 kernel: missing boundary checks in syscall/syscall32_nopage() | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-01-15 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2008-0957.html |
There are currently no legacy QID mappings associated with this CVE.