CVE-2008-5029
Last modified
CVE-2008-5029 is a vulnerability of currently unknown severity. The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 2.6.27.4 |
| Linux | Linux Kernel | 2.2.27 |
| Linux | Linux Kernel | 2.4.36 |
| Linux | Linux Kernel | 2.4.36.1 |
| Linux | Linux Kernel | 2.4.36.2 |
| Linux | Linux Kernel | 2.4.36.3 |
| Linux | Linux Kernel | 2.4.36.4 |
| Linux | Linux Kernel | 2.4.36.5 |
| Linux | Linux Kernel | 2.4.36.6 |
| Linux | Linux Kernel | 2.6 |
| Linux | Linux Kernel | 2.6.18 |
| Linux | Linux Kernel | 2.6.19.4 |
| Linux | Linux Kernel | 2.6.19.5 |
| Linux | Linux Kernel | 2.6.19.6 |
| Linux | Linux Kernel | 2.6.19.7 |
| Linux | Linux Kernel | 2.6.20.16 |
| Linux | Linux Kernel | 2.6.20.17 |
| Linux | Linux Kernel | 2.6.20.18 |
| Linux | Linux Kernel | 2.6.20.19 |
| Linux | Linux Kernel | 2.6.20.20 |
| Linux | Linux Kernel | 2.6.20.21 |
| Linux | Linux Kernel | 2.6.21.5 |
| Linux | Linux Kernel | 2.6.21.6 |
| Linux | Linux Kernel | 2.6.21.7 |
| Linux | Linux Kernel | 2.6.22 |
| Linux | Linux Kernel | 2.6.22.1 |
| Linux | Linux Kernel | 2.6.22.2 |
| Linux | Linux Kernel | 2.6.22.8 |
| Linux | Linux Kernel | 2.6.22.9 |
| Linux | Linux Kernel | 2.6.22.10 |
| Linux | Linux Kernel | 2.6.22.11 |
| Linux | Linux Kernel | 2.6.22.12 |
| Linux | Linux Kernel | 2.6.22.13 |
| Linux | Linux Kernel | 2.6.22.14 |
| Linux | Linux Kernel | 2.6.22.15 |
| Linux | Linux Kernel | 2.6.22.17 |
| Linux | Linux Kernel | 2.6.22.18 |
| Linux | Linux Kernel | 2.6.22.19 |
| Linux | Linux Kernel | 2.6.22.20 |
| Linux | Linux Kernel | 2.6.22.21 |
| Linux | Linux Kernel | 2.6.22.22 |
| Linux | Linux Kernel | 2.6.22_rc1 |
| Linux | Linux Kernel | 2.6.22_rc7 |
| Linux | Linux Kernel | 2.6.23 |
| Linux | Linux Kernel | 2.6.23.8 |
| Linux | Linux Kernel | 2.6.23.9 |
| Linux | Linux Kernel | 2.6.23.10 |
| Linux | Linux Kernel | 2.6.23.11 |
| Linux | Linux Kernel | 2.6.23.12 |
| Linux | Linux Kernel | 2.6.23.13 |
Showing 50 of 93 affected configurations. See NVD for the full list.
References
- http://darkircop.org/unix.cExploit
- http://darkircop.org/unix.cExploit
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5029?
How severe is CVE-2008-5029?
How do I fix CVE-2008-5029?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5023Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and S…
- CVE-2008-5024Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1…
- CVE-2008-5025Stack-based buffer overflow in the hfs_cat_find_brec functio…
- CVE-2008-5026Microsoft SharePoint uses URLs with the same hostname and po…
- CVE-2008-5027The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Mo…
- CVE-2008-5028Cross-site request forgery (CSRF) vulnerability in cmd.cgi i…
- CVE-2008-5030Heap-based buffer overflow in the cddb_read_disc_data functi…
- CVE-2008-5031Multiple integer overflows in Python 2.2.3 through 2.5.1, an…
- CVE-2008-5032Stack-based buffer overflow in VideoLAN VLC media player 0.5…
- CVE-2008-5033The chip_command function in drivers/media/video/tvaudio.c i…
- CVE-2008-5034master-filter in printfilters-ppd 2.13 allows local users to…
- CVE-2008-5035The Resource Monitoring and Control (RMC) daemon in IBM Hard…
Are you affected by CVE-2008-5029?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
