CVE-2008-3275

CVSS 5.5 - MEDIUM
Description

The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.

Affected Products
8
Vendor Product Version
linux linux_kernel All versions
debian debian_linux 4.0
canonical ubuntu_linux 6.06
canonical ubuntu_linux 7.04
canonical ubuntu_linux 7.10
canonical ubuntu_linux 8.04
suse suse_linux_enterprise_desktop 10
suse suse_linux_enterprise_server 10
Weakness Types
CWE-120
CVE Information
CVE ID:
CVE-2008-3275
Published:
2008-08-12
Modified:
2026-04-23
CVSS Score:
5.5
Severity:
MEDIUM
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Vendors
linux debian canonical suse
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL