CVE-2004-2607: Low severity Linux Linux kernel vulnerability
A numeric casting discrepancy in sdlaxfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2607?
The severity of CVE-2004-2607 is considered high due to its potential for local users to read sensitive portions of kernel memory.
How do I fix CVE-2004-2607?
To fix CVE-2004-2607, it is recommended to upgrade the Linux kernel to a version higher than 2.6.5 or 2.4.29-rc1.
What systems are affected by CVE-2004-2607?
CVE-2004-2607 affects Linux kernel versions 2.6.x up to 2.6.5 and 2.4.x up to 2.4.29-rc1.
How does CVE-2004-2607 exploit work?
CVE-2004-2607 exploits a numeric casting discrepancy that allows local users to bypass memory access restrictions.
Who is impacted by CVE-2004-2607?
Local users on systems running the affected versions of the Linux kernel may be impacted by CVE-2004-2607.