CVE-2008-3833
Summary
| CVE | CVE-2008-3833 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-03 17:41:40 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by splicing into an inode in order to create an executable file in a setgid directory, a different vulnerability than CVE-2008-4210. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.2.27 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.36.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | rc7 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.20 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20.21 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.20 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.21 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.22 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22_rc1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22_rc7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.25 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.26.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.26.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.26.3 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1653-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:025 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian update for linux-2.6 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Linux Kernel 'generic_file_splice_write()' Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red hat update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - CVE-2008-3833 kernel: remove SUID when splicing into an inode | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | |
| Bug 464450 – CVE-2008-3833 kernel: remove SUID when splicing into an inode | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| CONFIRM:http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.19.y.git;a=commit;h=8c34e2d63231d4bf4852bac8521883944d770fe3 | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-01-15 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2008-0957.html |
There are currently no legacy QID mappings associated with this CVE.