5.5

CVE-2007-6716

Exploit

fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.23
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04
DebianDebian Linux Version4.0
NovellLinux Desktop Version9
OpensuseOpensuse Version10.3
SuseSuse Linux Enterprise Desktop Version10 Updatesp2
SuseSuse Linux Enterprise Server Version10 Updatesp1
SuseSuse Linux Enterprise Server Version10 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.095
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
http://lkml.org/lkml/2007/7/30/448
Third Party Advisory
Exploit
Mailing List
http://www.openwall.com/lists/oss-security/2008/09/04/1
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/31515
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=461082
Patch
Third Party Advisory
Issue Tracking