Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-3275

19
FAUCET Score

CVE-2008-3275 describes a denial-of-service vulnerability in the Linux kernel's VFS implementation, specifically affecting versions before 2.6.25.15, including distributions like Canonical, Debian, and SUSE. The flaw allows a local attacker to exhaust the UBIFS orphan area by repeatedly attempting file creations within deleted directories. Rated as Medium severity (CVSS 5.5), this vulnerability requires local access and has a high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.6.25.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
7.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 92nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

debianpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.18-e.67
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.9-e.74
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: kernel-0:2.4.21-58.EL
View patch
redhatpatch availablevia redhat_api
Product: MRG for RHEL-5Fixed in: kernel-rt-0:2.6.24.7-81.el5rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-92.1.13.el5
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel-0:2.6.9-78.0.13.EL
View patch

Vendor Advisories (1)

redhatCVE-2008-3275Moderate

Linux kernel local filesystem DoS

Jul 2, 2008

References

git.kernel.org
kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.25.15
Broken Link
lists.opensuse.org / opensuse-security-announce/2008-10/msg00001.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-10/msg00003.html
Mailing ListThird Party Advisory
lkml.org / lkml/2008/7/2/83
ExploitMailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
secunia.com / advisories/31551
Broken Link
secunia.com / advisories/31614
Broken Link
secunia.com / advisories/31836
Broken Link
secunia.com / advisories/31881
Broken Link
secunia.com / advisories/32023
Broken Link
secunia.com / advisories/32104
Broken Link
secunia.com / advisories/32190
Broken Link
secunia.com / advisories/32344
Broken Link
secunia.com / advisories/33201
Broken Link
secunia.com / advisories/33280
Broken Link
secunia.com / advisories/33556
Broken Link
exchange.xforce.ibmcloud.com / vulnerabilities/44410
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10744
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6551
Third Party Advisory
usn.ubuntu.com / 637-1
Third Party Advisory
debian.org / security/2008/dsa-1630
PatchThird Party Advisory
debian.org / security/2008/dsa-1636
PatchThird Party Advisory
mandriva.com / security/advisories
Broken Link
redhat.com / support/errata/RHSA-2008-0787.html
Broken Link
redhat.com / support/errata/RHSA-2008-0857.html
Broken Link
redhat.com / support/errata/RHSA-2008-0885.html
Broken Link
redhat.com / support/errata/RHSA-2008-0973.html
Broken Link
redhat.com / support/errata/RHSA-2009-0014.html
Broken Link
securityfocus.com / bid/30647
PatchThird Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
vupen.com / english/advisories/2008/2430
Broken Link