>> Linux Kernel Fault Handler Range Check Memory Corruption Vulnerability
Title : Linux Kernel Fault Handler Range Check Memory Corruption Vulnerability VUPEN ID : VUPEN/ADV-2008-0445 CVE ID : CVE-2008-0007
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-02-07
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by local attackers to bypass security restrictions, cause a denial of service or potentially gain elevated privileges. This issue is caused due to insufficient range checks in certain fault handlers within the "drivers/char/drm/drm_vm.c", "drivers/char/mspec.c", "fs/ncpfs/mmap.c", "kernel/relay.c", "mm/mmap.c", "sound/oss/via82cxxx_audio.c", "sound/usb/usx2y/usX2Yhwdep.c" and "sound/usb/usx2y/usx2yhwdeppcm.c" files, which could be exploited by local attackers to potentially read or write arbitrary kernel memory.