CVE-2008-4302 describes a denial-of-service vulnerability in the Linux kernel's splice subsystem (fs/splice.c) affecting versions before 2.6.22.2, including various Debian and Red Hat distributions. The flaw occurs when the add_to_page_cache_lru function fails, leading to an attempt to unlock an already unlocked page, which results in a kernel BUG and system crash. This is a medium-severity vulnerability (CVSS 5.5) with a local attack vector, low attack complexity, and high impact on availability. While there is no evidence of active exploitation, a proof-of-concept exploit is available on ExploitDB, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.22.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.