vendor:
Linux Kernel
by:
qaaz
7.2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Linux Kernel
Affected Version From: 2.6.23
Affected Version To: 2.6.24
Patch Exists: YES
Related CWE: CVE-2008-0600
CPE: o:linux:linux_kernel
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2008
Linux vmsplice Local Root Exploit
This exploit is a local privilege escalation vulnerability in the Linux kernel. It is based on a race condition in the vmsplice system call. The exploit uses a trampoline code to overwrite the uid and gid of the current process, allowing it to gain root privileges. The exploit works on Linux versions 2.6.23 to 2.6.24.
Mitigation:
The vulnerability can be mitigated by applying the appropriate security patches for the affected versions of the Linux kernel.