CVE-2008-7256 is a denial-of-service vulnerability affecting the Linux kernel before version 2.6.28-rc8, specifically when strict overcommit is enabled and CONFIG_SECURITY is disabled. It stems from improper handling of shmemfs object exports by knfsd, leading to a NULL pointer dereference and knfsd crash. The vulnerability has a low CVSS score of 1.2, indicating local access with high attack complexity and only partial availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.28CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:rc7:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* | ||
2.6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:* | ||
2.6.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:* | ||
2.6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.