CVE-2008-2137 - CVE House
Back to Database
Status published Medium CVE-2008-2137

The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check...

Vulnerability Description

The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap MAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mmap calls.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-2137

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

debian linux, linux kernel
Vulnerable Versions:
4.0, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.9, 2.6.10, 2.6.11, 2.6.11.4, 2.6.11.5, 2.6.11.6, 2.6.11.7, 2.6.11.8, 2.6.11.11, 2.6.11.12, 2.6.12, 2.6.12.1, 2.6.12.2, 2.6.12.3, 2.6.12.4, 2.6.12.5, 2.6.12.6, 2.6.12.12, 2.6.12.22, 2.6.13, 2.6.13.1, 2.6.13.2, 2.6.13.3, 2.6.13.4, 2.6.14, 2.6.14.1, 2.6.14.2, 2.6.14.3, 2.6.14.4, 2.6.14.5, 2.6.15, 2.6.15.1, 2.6.15.2, 2.6.15.3, 2.6.15.4, 2.6.15.5, 2.6.15.11, 2.6.16, 2.6.16.13, 2.6.16.27, 2.6.17, 2.6.17.1, 2.6.17.2, 2.6.17.3, 2.6.17.5, 2.6.17.6, 2.6.17.7, 2.6.17.8, 2.6.17.10, 2.6.17.11, 2.6.17.12, 2.6.17.13, 2.6.17.14, 2.6.18, 2.6.18.1, 2.6.18.3, 2.6.18.4, 2.6.19, 2.6.19.1, 2.6.19.2, 2.6.20, 2.6.20.1, 2.6.20.2, 2.6.20.3, 2.6.20.4, 2.6.20.5, 2.6.20.8, 2.6.20.9, 2.6.20.11, 2.6.20.13, 2.6.20.15, 2.6.21, 2.6.21.1, 2.6.21.2, 2.6.21.4, 2.6.21.6, 2.6.21.7, 2.6.22, 2.6.22.3, 2.6.22.4, 2.6.22.5, 2.6.22.6, 2.6.22.7, 2.6.22.8, 2.6.22.11, 2.6.22.12, 2.6.22.13, 2.6.22.14, 2.6.22.15, 2.6.22.16, 2.6.22.17, 2.6.23, 2.6.23.1, 2.6.23.2, 2.6.23.3, 2.6.23.4, 2.6.23.5, 2.6.23.6, 2.6.23.7, 2.6.23.9, 2.6.23.14, 2.6.24.1, 2.6.24.2, 2.6.25, 2.6.25.1, 2.6.25.2

Timeline

Official Publish: May 29th, 2008
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.