CVE-2008-3832: Null Pointer Dereference

Published Oct 1, 2008
·
Updated

A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of service (NULL pointer dereference and system crash or hang) via a call to the utracecontrol function.

Other sources

Reported by Michael Simms:

Any user can crash init with a single command

Version-Release number of selected component (if applicable): Fedora 9, patched to latest as of 90 minutes ago

How reproducible: Always. May have to run the command 2-3 times but it always crashes the kernel in the end.

Steps to Reproduce: 1.as ANY user - start a shell 2.gdb anyexecutable 1 3.There will be a kerneloops and usually a kernel crash or hang

Actual results: Kernel blows up

Expected results: Kernel doesnt blow up, permission denied for process init

Additional info:

Red Hat

Affected Software

68 affected components
redhat Fedora=8
Linux Linux kernel<=2.6.26.4
Linux Linux kernel=2.2.27
Linux Linux kernel=2.4.36
Linux Linux kernel=2.4.36.1
Linux Linux kernel=2.4.36.2
Linux Linux kernel=2.4.36.3
Linux Linux kernel=2.4.36.4
Linux Linux kernel=2.4.36.5
Linux Linux kernel=2.4.36.6
Linux Linux kernel=2.6
Linux Linux kernel=2.6.18
Linux Linux kernel=2.6.18-rc1
Linux Linux kernel=2.6.18-rc2
Linux Linux kernel=2.6.18-rc3
Linux Linux kernel=2.6.18-rc4
Linux Linux kernel=2.6.18-rc5
Linux Linux kernel=2.6.18-rc6
Linux Linux kernel=2.6.18-rc7
Linux Linux kernel=2.6.19.4
Linux Linux kernel=2.6.19.5
Linux Linux kernel=2.6.19.6
Linux Linux kernel=2.6.19.7
Linux Linux kernel=2.6.20.16
Linux Linux kernel=2.6.20.17
Linux Linux kernel=2.6.20.18
Linux Linux kernel=2.6.20.19
Linux Linux kernel=2.6.20.20
Linux Linux kernel=2.6.20.21
Linux Linux kernel=2.6.21.5
Linux Linux kernel=2.6.21.6
Linux Linux kernel=2.6.21.7
Linux Linux kernel=2.6.22
Linux Linux kernel=2.6.22.1
Linux Linux kernel=2.6.22.2
Linux Linux kernel=2.6.22.8
Linux Linux kernel=2.6.22.9
Linux Linux kernel=2.6.22.10
Linux Linux kernel=2.6.22.11
Linux Linux kernel=2.6.22.12
Linux Linux kernel=2.6.22.13
Linux Linux kernel=2.6.22.14
Linux Linux kernel=2.6.22.15
Linux Linux kernel=2.6.22.17
Linux Linux kernel=2.6.22.18
Linux Linux kernel=2.6.22.19
Linux Linux kernel=2.6.22.20
Linux Linux kernel=2.6.22.21
Linux Linux kernel=2.6.22.22
Linux Linux kernel=2.6.22_rc1
Linux Linux kernel=2.6.22_rc7
Linux Linux kernel=2.6.23
Linux Linux kernel=2.6.24
Linux Linux kernel=2.6.25
Linux Linux kernel=2.6.26
Linux Linux kernel=2.6.26.1
Linux Linux kernel=2.6.26.2
Linux Linux kernel=2.6.26.3
redhat Fedora=9
Linux Linux kernel=2.6.23.8
Linux Linux kernel=2.6.23.9
Linux Linux kernel=2.6.23.10
Linux Linux kernel=2.6.23.11
Linux Linux kernel=2.6.23.12
Linux Linux kernel=2.6.23.13
Linux Linux kernel=2.6.23.15
Linux Linux kernel=2.6.23.16
Linux Linux kernel=2.6.23.17

Event History

Oct 1, 2008
Data Sourced
via Red Hat·12:44 AM
DescriptionSeverityAffected Software
Oct 3, 2008
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
Description
Data Sourced
05:41 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2008-3832?

CVE-2008-3832 is classified as a high severity vulnerability due to its potential to cause denial of service.

2

How do I fix CVE-2008-3832?

To fix CVE-2008-3832, update your Fedora system to versions 2.6.26.5-28 or later for Fedora 8 and 2.6.26.5-45 or later for Fedora 9.

3

What systems are affected by CVE-2008-3832?

CVE-2008-3832 affects local users of Fedora 8 and Fedora 9 systems running specific versions of the Linux kernel.

4

How does CVE-2008-3832 exploit the system?

CVE-2008-3832 exploits the system by allowing a null pointer dereference through the utrace_control function, leading to a system crash or hang.

5

When was CVE-2008-3832 reported?

CVE-2008-3832 was reported on October 2, 2008, and is tied to vulnerabilities in the utrace subsystem of the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203