{"api_version":"1","generated_at":"2026-07-23T05:39:39+00:00","cve":"CVE-2008-4302","urls":{"html":"https://cve.report/CVE-2008-4302","api":"https://cve.report/api/cve/CVE-2008-4302.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4302","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4302"},"summary":{"title":"CVE-2008-4302","description":"fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-29 17:17:29","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-667","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2008/09/16/10","name":"http://www.openwall.com/lists/oss-security/2008/09/16/10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE request: kernel: splice: fix bad unlock_page() in error case","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32759","name":"http://secunia.com/advisories/32759","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1653","name":"http://www.debian.org/security/2008/dsa-1653","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1653-1 linux-2.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2008:025","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32237","name":"http://secunia.com/advisories/32237","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Debian update for linux-2.6 - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31201","name":"http://www.securityfocus.com/bid/31201","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Linux Kernel 'add_to_page_cache_lru()' Local Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10547","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10547","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lkml.org/lkml/2007/7/20/168","name":"http://lkml.org/lkml/2007/7/20/168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"LKML: Jens Axboe: [PATCH] splice: fix bad unlock_page() in error case","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45191","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45191","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0957.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0957.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32485","name":"http://secunia.com/advisories/32485","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Red hat update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=462434","name":"https://bugzilla.redhat.com/show_bug.cgi?id=462434","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug 462434 – CVE-2008-4302 kernel: splice: fix bad unlock_page() in error case","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.2","name":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=6a860c979b35469e4d77da781a96bdb2ca05ae64","name":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=6a860c979b35469e4d77da781a96bdb2ca05ae64","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.juniper.net/security/auto/vulnerabilities/vuln31201.html","name":"http://www.juniper.net/security/auto/vulnerabilities/vuln31201.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404 : Page not found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=6a860c979b35469e4d77da781a96bdb2ca05ae64","name":"CONFIRM:http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=6a860c979b35469e4d77da781a96bdb2ca05ae64","refsource":"MITRE","tags":[],"title":"","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4302","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4302","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4302","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4302","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4302","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-4302","organization":"Red Hat","lastmodified":"2009-01-15","contributor":"Tomas Hoger","statementText":"This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2008-0957.html","cve_year":"2008","cve_id":"4302","crc32":"6af1b89a"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:08:35.153Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[oss-security] 20080916 CVE request: kernel: splice: fix bad unlock_page() in error case","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2008/09/16/10"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=6a860c979b35469e4d77da781a96bdb2ca05ae64"},{"name":"32485","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32485"},{"name":"32237","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32237"},{"name":"RHSA-2008:0957","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0957.html"},{"name":"linux-kernel-addtopagecachelru-dos(45191)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45191"},{"name":"DSA-1653","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1653"},{"name":"oval:org.mitre.oval:def:10547","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10547"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=462434"},{"name":"32759","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32759"},{"name":"[linux-kernel] 20070720 [PATCH] splice: fix bad unlock_page() in error case","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lkml.org/lkml/2007/7/20/168"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.2"},{"name":"SUSE-SR:2008:025","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"},{"name":"31201","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31201"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.juniper.net/security/auto/vulnerabilities/vuln31201.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-09-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"[oss-security] 20080916 CVE request: kernel: splice: fix bad unlock_page() in error case","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2008/09/16/10"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=6a860c979b35469e4d77da781a96bdb2ca05ae64"},{"name":"32485","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32485"},{"name":"32237","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32237"},{"name":"RHSA-2008:0957","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0957.html"},{"name":"linux-kernel-addtopagecachelru-dos(45191)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45191"},{"name":"DSA-1653","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1653"},{"name":"oval:org.mitre.oval:def:10547","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10547"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=462434"},{"name":"32759","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32759"},{"name":"[linux-kernel] 20070720 [PATCH] splice: fix bad unlock_page() in error case","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lkml.org/lkml/2007/7/20/168"},{"tags":["x_refsource_CONFIRM"],"url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.2"},{"name":"SUSE-SR:2008:025","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"},{"name":"31201","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31201"},{"tags":["x_refsource_MISC"],"url":"http://www.juniper.net/security/auto/vulnerabilities/vuln31201.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4302","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[oss-security] 20080916 CVE request: kernel: splice: fix bad unlock_page() in error case","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2008/09/16/10"},{"name":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=6a860c979b35469e4d77da781a96bdb2ca05ae64","refsource":"CONFIRM","url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=6a860c979b35469e4d77da781a96bdb2ca05ae64"},{"name":"32485","refsource":"SECUNIA","url":"http://secunia.com/advisories/32485"},{"name":"32237","refsource":"SECUNIA","url":"http://secunia.com/advisories/32237"},{"name":"RHSA-2008:0957","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0957.html"},{"name":"linux-kernel-addtopagecachelru-dos(45191)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45191"},{"name":"DSA-1653","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1653"},{"name":"oval:org.mitre.oval:def:10547","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10547"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=462434","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=462434"},{"name":"32759","refsource":"SECUNIA","url":"http://secunia.com/advisories/32759"},{"name":"[linux-kernel] 20070720 [PATCH] splice: fix bad unlock_page() in error case","refsource":"MLIST","url":"http://lkml.org/lkml/2007/7/20/168"},{"name":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.2","refsource":"CONFIRM","url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.2"},{"name":"SUSE-SR:2008:025","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"},{"name":"31201","refsource":"BID","url":"http://www.securityfocus.com/bid/31201"},{"name":"http://www.juniper.net/security/auto/vulnerabilities/vuln31201.html","refsource":"MISC","url":"http://www.juniper.net/security/auto/vulnerabilities/vuln31201.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4302","datePublished":"2008-09-29T17:00:00.000Z","dateReserved":"2008-09-29T00:00:00.000Z","dateUpdated":"2024-08-07T10:08:35.153Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-29 17:17:29","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-667","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"2.6.22.2","matchCriteriaId":"3964F496-69A9-4EDE-B659-442233AC27C3"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*","matchCriteriaId":"1D8B549B-E57B-4DFE-8A13-CAB06B5356B3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4302","Ordinal":"1","Title":"CVE-2008-4302","CVE":"CVE-2008-4302","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4302","Ordinal":"1","NoteData":"fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.","Type":"Description","Title":"CVE-2008-4302"},{"CveYear":"2008","CveId":"4302","Ordinal":"2","NoteData":"2008-09-29","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4302","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}