CVE-2008-2812: Null Pointer Dereference
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) pppasync.c, (5) pppsynctty.c, (6) slip.c, (7) wan/x25asy.c, and (8) wireless/strip.c in drivers/net/.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2812?
CVE-2008-2812 is classified as a high severity vulnerability due to its potential to cause system crashes and privilege escalation.
How do I fix CVE-2008-2812?
To fix CVE-2008-2812, update the Linux kernel to version 2.6.25.10 or later as specified in the vulnerability report.
What platforms are affected by CVE-2008-2812?
CVE-2008-2812 affects several Linux distributions including Ubuntu 6.06, 7.04, 7.10, 8.04, and openSUSE 10.3 and 11.0.
Can CVE-2008-2812 be exploited remotely?
CVE-2008-2812 primarily allows local users to exploit the vulnerability, making remote exploitation unlikely.
What are the potential impacts of CVE-2008-2812?
The impacts of CVE-2008-2812 include potential system crashes and unauthorized privilege escalation.