{"api_version":"1","generated_at":"2026-07-23T12:42:17+00:00","cve":"CVE-2008-3535","urls":{"html":"https://cve.report/CVE-2008-3535","api":"https://cve.report/api/cve/CVE-2008-3535.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3535","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3535"},"summary":{"title":"CVE-2008-3535","description":"Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-08-08 19:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-193","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2","name":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404: File not found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://secunia.com/advisories/32190","name":"http://secunia.com/advisories/32190","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for kernel - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1636","name":"http://www.debian.org/security/2008/dsa-1636","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1636-1 linux-2.6.24","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44492","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44492","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31132","name":"http://www.securityfocus.com/bid/31132","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel 'iov_iter_advance()' Page Fault  Local Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.lkml.org/lkml/2008/7/30/446","name":"http://www.lkml.org/lkml/2008/7/30/446","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"LKML: Alexey Dobriyan: 2.6.27-rc1: IP: iov_iter_advance+0x2e/0x90","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32393","name":"http://secunia.com/advisories/32393","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Ubuntu update for linux - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31881","name":"http://secunia.com/advisories/31881","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for linux-2.6.24 - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-659-1","name":"http://www.ubuntu.com/usn/usn-659-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-659-1: Linux kernel vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://mirror.celinuxforum.org/gitstat/commit-detail.php?commit=94ad374a0751f40d25e22e036c37f7263569d24c","name":"http://mirror.celinuxforum.org/gitstat/commit-detail.php?commit=94ad374a0751f40d25e22e036c37f7263569d24c","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0857.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0857.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3535","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3535","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"6.06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"7.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"8.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.27","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.27","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-3535","organization":"Red Hat","lastmodified":"2009-01-15","contributor":"Tomas Hoger","statementText":"This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5. It was addressed in Red Hat Enterprise MRG for RHEL-5 via: https://rhn.redhat.com/errata/RHSA-2008-0857.html","cve_year":"2008","cve_id":"3535","crc32":"1330c2b2"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:45:17.967Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"32190","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32190"},{"name":"32393","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32393"},{"name":"DSA-1636","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1636"},{"name":"31132","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31132"},{"name":"linux-kernel-ioviteradvance-dos(44492)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44492"},{"name":"31881","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31881"},{"name":"USN-659-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-659-1"},{"name":"RHSA-2008:0857","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0857.html"},{"name":"[linux-kernel] 20080730 2.6.27-rc1: IP: iov_iter_advance+0x2e/0x90","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.lkml.org/lkml/2008/7/30/446"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://mirror.celinuxforum.org/gitstat/commit-detail.php?commit=94ad374a0751f40d25e22e036c37f7263569d24c"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"32190","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32190"},{"name":"32393","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32393"},{"name":"DSA-1636","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1636"},{"name":"31132","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31132"},{"name":"linux-kernel-ioviteradvance-dos(44492)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44492"},{"name":"31881","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31881"},{"name":"USN-659-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-659-1"},{"name":"RHSA-2008:0857","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0857.html"},{"name":"[linux-kernel] 20080730 2.6.27-rc1: IP: iov_iter_advance+0x2e/0x90","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.lkml.org/lkml/2008/7/30/446"},{"tags":["x_refsource_CONFIRM"],"url":"http://mirror.celinuxforum.org/gitstat/commit-detail.php?commit=94ad374a0751f40d25e22e036c37f7263569d24c"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3535","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"32190","refsource":"SECUNIA","url":"http://secunia.com/advisories/32190"},{"name":"32393","refsource":"SECUNIA","url":"http://secunia.com/advisories/32393"},{"name":"DSA-1636","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1636"},{"name":"31132","refsource":"BID","url":"http://www.securityfocus.com/bid/31132"},{"name":"linux-kernel-ioviteradvance-dos(44492)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44492"},{"name":"31881","refsource":"SECUNIA","url":"http://secunia.com/advisories/31881"},{"name":"USN-659-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-659-1"},{"name":"RHSA-2008:0857","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0857.html"},{"name":"[linux-kernel] 20080730 2.6.27-rc1: IP: iov_iter_advance+0x2e/0x90","refsource":"MLIST","url":"http://www.lkml.org/lkml/2008/7/30/446"},{"name":"http://mirror.celinuxforum.org/gitstat/commit-detail.php?commit=94ad374a0751f40d25e22e036c37f7263569d24c","refsource":"CONFIRM","url":"http://mirror.celinuxforum.org/gitstat/commit-detail.php?commit=94ad374a0751f40d25e22e036c37f7263569d24c"},{"name":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3535","datePublished":"2008-08-08T19:00:00.000Z","dateReserved":"2008-08-07T00:00:00.000Z","dateUpdated":"2024-08-07T09:45:17.967Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-08-08 19:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-193","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"2.6.27","matchCriteriaId":"BF554042-72C3-4933-A7FC-62778030A785"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.27:-:*:*:*:*:*:*","matchCriteriaId":"B6115C56-3A6D-4A62-A3F1-8AC8E915FC3D"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.27:rc1:*:*:*:*:*:*","matchCriteriaId":"F8B59FCD-8161-48EF-844D-8FA1AB2FAA76"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*","matchCriteriaId":"454A5D17-B171-4F1F-9E0B-F18D1E5CA9FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*","matchCriteriaId":"823BF8BE-2309-4F67-A5E2-EAD98F723468"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*","matchCriteriaId":"7EBFE35C-E243-43D1-883D-4398D71763CC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3535","Ordinal":"1","Title":"CVE-2008-3535","CVE":"CVE-2008-3535","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3535","Ordinal":"1","NoteData":"Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.","Type":"Description","Title":"CVE-2008-3535"},{"CveYear":"2008","CveId":"3535","Ordinal":"2","NoteData":"2008-08-08","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3535","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}