CVE-2008-3832: Null Pointer Dereference
A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of service (NULL pointer dereference and system crash or hang) via a call to the utracecontrol function.
Other sources
Reported by Michael Simms:
Any user can crash init with a single command
Version-Release number of selected component (if applicable): Fedora 9, patched to latest as of 90 minutes ago
How reproducible: Always. May have to run the command 2-3 times but it always crashes the kernel in the end.
Steps to Reproduce: 1.as ANY user - start a shell 2.gdb anyexecutable 1 3.There will be a kerneloops and usually a kernel crash or hang
Actual results: Kernel blows up
Expected results: Kernel doesnt blow up, permission denied for process init
Additional info:
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3832?
CVE-2008-3832 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2008-3832?
To fix CVE-2008-3832, update your Fedora system to versions 2.6.26.5-28 or later for Fedora 8 and 2.6.26.5-45 or later for Fedora 9.
What systems are affected by CVE-2008-3832?
CVE-2008-3832 affects local users of Fedora 8 and Fedora 9 systems running specific versions of the Linux kernel.
How does CVE-2008-3832 exploit the system?
CVE-2008-3832 exploits the system by allowing a null pointer dereference through the utrace_control function, leading to a system crash or hang.
When was CVE-2008-3832 reported?
CVE-2008-3832 was reported on October 2, 2008, and is tied to vulnerabilities in the utrace subsystem of the Linux kernel.