CVE-2008-1294
UnknownEPSS 0.53%
Last modified
CVE-2008-1294 is a vulnerability of currently unknown severity. Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | <= 2.6.21 | Rc7 |
| Linux | Linux Kernel | 2.6.2 | — |
| Linux | Linux Kernel | 2.6.16 | — |
| Linux | Linux Kernel | 2.6.16.1 | — |
| Linux | Linux Kernel | 2.6.16.2 | — |
| Linux | Linux Kernel | 2.6.16.3 | — |
| Linux | Linux Kernel | 2.6.16.4 | — |
| Linux | Linux Kernel | 2.6.16.5 | — |
| Linux | Linux Kernel | 2.6.16.6 | — |
| Linux | Linux Kernel | 2.6.16.7 | — |
| Linux | Linux Kernel | 2.6.16.8 | — |
| Linux | Linux Kernel | 2.6.16.9 | — |
| Linux | Linux Kernel | 2.6.16.10 | — |
| Linux | Linux Kernel | 2.6.16.11 | — |
| Linux | Linux Kernel | 2.6.16.12 | — |
| Linux | Linux Kernel | 2.6.16.13 | — |
| Linux | Linux Kernel | 2.6.16.14 | — |
| Linux | Linux Kernel | 2.6.16.15 | — |
| Linux | Linux Kernel | 2.6.16.16 | — |
| Linux | Linux Kernel | 2.6.16.17 | — |
| Linux | Linux Kernel | 2.6.16.18 | — |
| Linux | Linux Kernel | 2.6.16.19 | — |
| Linux | Linux Kernel | 2.6.16.20 | — |
| Linux | Linux Kernel | 2.6.16.21 | — |
| Linux | Linux Kernel | 2.6.16.22 | — |
| Linux | Linux Kernel | 2.6.16.23 | — |
| Linux | Linux Kernel | 2.6.16.24 | — |
| Linux | Linux Kernel | 2.6.16.25 | — |
| Linux | Linux Kernel | 2.6.16.26 | — |
| Linux | Linux Kernel | 2.6.16.27 | — |
| Linux | Linux Kernel | 2.6.16.28 | — |
| Linux | Linux Kernel | 2.6.16.29 | — |
| Linux | Linux Kernel | 2.6.16.30 | — |
| Linux | Linux Kernel | 2.6.16.31 | — |
| Linux | Linux Kernel | 2.6.16.32 | — |
| Linux | Linux Kernel | 2.6.16.33 | — |
| Linux | Linux Kernel | 2.6.16.34 | — |
| Linux | Linux Kernel | 2.6.16.35 | — |
| Linux | Linux Kernel | 2.6.16.36 | — |
| Linux | Linux Kernel | 2.6.16.37 | — |
| Linux | Linux Kernel | 2.6.16.38 | — |
| Linux | Linux Kernel | 2.6.16.39 | — |
| Linux | Linux Kernel | 2.6.16.40 | — |
| Linux | Linux Kernel | 2.6.16.41 | — |
| Linux | Linux Kernel | 2.6.16.43 | — |
| Linux | Linux Kernel | 2.6.16.44 | — |
| Linux | Linux Kernel | 2.6.16.45 | — |
| Linux | Linux Kernel | 2.6.16.46 | — |
| Linux | Linux Kernel | 2.6.16.47 | — |
| Linux | Linux Kernel | 2.6.16.48 | — |
Showing 50 of 105 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1294?
Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.
How severe is CVE-2008-1294?
Severity scoring for CVE-2008-1294 is pending analysis. The EPSS model estimates a 0.53% probability of exploitation in the next 30 days.
How do I fix CVE-2008-1294?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1288IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow loca…
- CVE-2008-1289Multiple buffer overflows in Asterisk Open Source 1.4.x befo…
- CVE-2008-1290ViewVC before 1.0.5 includes "all-forbidden" files within se…
- CVE-2008-1291ViewVC before 1.0.5 stores sensitive information under the w…
- CVE-2008-1292ViewVC before 1.0.5 provides revision metadata without prope…
- CVE-2008-1293ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passe…
- CVE-2008-1295SQL injection vulnerability in archives.php in Gregory Kokan…
- CVE-2008-1296Multiple cross-site scripting (XSS) vulnerabilities in Encap…
- CVE-2008-1297SQL injection vulnerability in index.php in the eWriting (co…
- CVE-2008-1298SQL injection vulnerability in Hadith module for PHP-Nuke al…
- CVE-2008-1299Cross-site scripting (XSS) vulnerability in SolutionSearch.d…6.1
- CVE-2008-1300Cross-site scripting (XSS) vulnerability in the Logfile View…
Are you affected by CVE-2008-1294?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
