CVE-2008-0001
Last modified
CVE-2008-0001 is a vulnerability of currently unknown severity. VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 2.6.22.15 |
| Linux | Linux Kernel | 2.6.0 |
| Linux | Linux Kernel | 2.6.1 |
| Linux | Linux Kernel | 2.6.2 |
| Linux | Linux Kernel | 2.6.3 |
| Linux | Linux Kernel | 2.6.4 |
| Linux | Linux Kernel | 2.6.5 |
| Linux | Linux Kernel | 2.6.6 |
| Linux | Linux Kernel | 2.6.7 |
| Linux | Linux Kernel | 2.6.8 |
| Linux | Linux Kernel | 2.6.8.1 |
| Linux | Linux Kernel | 2.6.9 |
| Linux | Linux Kernel | 2.6.10 |
| Linux | Linux Kernel | 2.6.11 |
| Linux | Linux Kernel | 2.6.11.1 |
| Linux | Linux Kernel | 2.6.11.2 |
| Linux | Linux Kernel | 2.6.11.3 |
| Linux | Linux Kernel | 2.6.11.4 |
| Linux | Linux Kernel | 2.6.11.5 |
| Linux | Linux Kernel | 2.6.11.6 |
| Linux | Linux Kernel | 2.6.11.7 |
| Linux | Linux Kernel | 2.6.11.8 |
| Linux | Linux Kernel | 2.6.11.9 |
| Linux | Linux Kernel | 2.6.11.10 |
| Linux | Linux Kernel | 2.6.11.11 |
| Linux | Linux Kernel | 2.6.11.12 |
| Linux | Linux Kernel | 2.6.12 |
| Linux | Linux Kernel | 2.6.12.1 |
| Linux | Linux Kernel | 2.6.12.2 |
| Linux | Linux Kernel | 2.6.12.3 |
| Linux | Linux Kernel | 2.6.12.4 |
| Linux | Linux Kernel | 2.6.12.5 |
| Linux | Linux Kernel | 2.6.12.6 |
| Linux | Linux Kernel | 2.6.13 |
| Linux | Linux Kernel | 2.6.13.1 |
| Linux | Linux Kernel | 2.6.13.2 |
| Linux | Linux Kernel | 2.6.13.3 |
| Linux | Linux Kernel | 2.6.13.4 |
| Linux | Linux Kernel | 2.6.13.5 |
| Linux | Linux Kernel | 2.6.14 |
| Linux | Linux Kernel | 2.6.14.1 |
| Linux | Linux Kernel | 2.6.14.2 |
| Linux | Linux Kernel | 2.6.14.3 |
| Linux | Linux Kernel | 2.6.14.4 |
| Linux | Linux Kernel | 2.6.14.5 |
| Linux | Linux Kernel | 2.6.14.6 |
| Linux | Linux Kernel | 2.6.14.7 |
| Linux | Linux Kernel | 2.6.15 |
| Linux | Linux Kernel | 2.6.15.1 |
| Linux | Linux Kernel | 2.6.15.2 |
Showing 50 of 209 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/28485Vendor Advisory
- http://secunia.com/advisories/28558Vendor Advisory
- http://secunia.com/advisories/28626Vendor Advisory
- http://secunia.com/advisories/28628Vendor Advisory
- http://secunia.com/advisories/28643Vendor Advisory
- http://secunia.com/advisories/28664Vendor Advisory
- http://secunia.com/advisories/28706Vendor Advisory
- http://secunia.com/advisories/28748Vendor Advisory
- http://secunia.com/advisories/28806Vendor Advisory
- http://secunia.com/advisories/28971Vendor Advisory
- http://secunia.com/advisories/29245Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0151Vendor Advisory
- http://secunia.com/advisories/28485Vendor Advisory
- http://secunia.com/advisories/28558Vendor Advisory
- http://secunia.com/advisories/28626Vendor Advisory
- http://secunia.com/advisories/28628Vendor Advisory
- http://secunia.com/advisories/28643Vendor Advisory
- http://secunia.com/advisories/28664Vendor Advisory
- http://secunia.com/advisories/28706Vendor Advisory
- http://secunia.com/advisories/28748Vendor Advisory
- http://secunia.com/advisories/28806Vendor Advisory
- http://secunia.com/advisories/28971Vendor Advisory
- http://secunia.com/advisories/29245Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0151Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0001?
How severe is CVE-2008-0001?
How do I fix CVE-2008-0001?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-0002Apache Tomcat 6.0.0 through 6.0.15 processes parameters in t…
- CVE-2008-0003Stack-based buffer overflow in the PAMBasicAuthenticator::PA…
- CVE-2008-0004Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-0005mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before…
- CVE-2008-0006Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) t…
- CVE-2008-0007Linux kernel before 2.6.22.17, when using certain drivers th…
Are you affected by CVE-2008-0001?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
