Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-2136

23
FAUCET Score

CVE-2008-2136 describes a memory leak vulnerability in the Linux kernel's Simple Internet Transition (SIT) tunnel interface, specifically within the ipip6_rcv function. This flaw affects Linux kernel versions 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, impacting various distributions including Canonical and Debian. Remote attackers can exploit this by sending crafted network traffic to a SIT tunnel interface, leading to memory consumption and a denial of service. The vulnerability carries a CVSS score of 7.8 (High), indicating a critical severity. It requires no authentication (AV:N/AC:L/Au:N) and can be exploited with low complexity, resulting in a complete loss of availability (A:C). The FAUCET Risk Score is 91/100, highlighting its significant potential impact. Despite its high severity, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention from the broader security community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.4.0, < 2.4.36.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 2.6.0, < 2.6.25.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.8HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.93%
Probability of exploitation in next 30 days
EPSS Percentile
91.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0493 is in the 85th percentile among its peer group of 51,466 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: MRG for RHEL-5Fixed in: kernel-rt-0:2.6.24.7-74.el5rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.18-e.67
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.9-e.74
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: kernel-0:2.4.21-58.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel-0:2.6.9-67.0.22.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-92.1.10.el5
View patch

Vendor Advisories (1)

redhatCVE-2008-2136Important

kernel: sit memory leak

May 9, 2008

References

kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.25.3
Vendor Advisory
lists.opensuse.org / opensuse-security-announce/2008-06/msg00006.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-07/msg00002.html
Third Party Advisory
marc.info
Mailing ListThird Party Advisory
secunia.com / advisories/30198
Third Party Advisory
secunia.com / advisories/30241
Third Party Advisory
secunia.com / advisories/30276
Third Party Advisory
secunia.com / advisories/30368
Third Party Advisory
secunia.com / advisories/30499
Third Party Advisory
secunia.com / advisories/30818
Third Party Advisory
secunia.com / advisories/30962
Third Party Advisory
secunia.com / advisories/31107
Third Party Advisory
secunia.com / advisories/31198
Third Party Advisory
secunia.com / advisories/31341
Third Party Advisory
secunia.com / advisories/31628
Third Party Advisory
secunia.com / advisories/31689
Third Party Advisory
secunia.com / advisories/33201
Third Party Advisory
secunia.com / advisories/33280
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/42451
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11038
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6503
Broken Link
support.avaya.com / elmodocs2/security/ASA-2008-362.htm
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-May/msg00294.html
Third Party Advisory
wiki.rpath.com / wiki/Advisories:rPSA-2008-0169
Broken Link
debian.org / security/2008/dsa-1588
Third Party Advisory
kernel.org / pub/linux/kernel/v2.4/ChangeLog-2.4.36.5
Vendor Advisory
kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.25.3
Vendor Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0585.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0607.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0612.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0787.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0973.html
Third Party Advisory
securityfocus.com / bid/29235
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-625-1
Third Party Advisory
vupen.com / english/advisories/2008/1543/references
Third Party Advisory
vupen.com / english/advisories/2008/1716/references
Third Party Advisory