Candidate: CVE-2008-3528 PublicDate: 2008-09-27 10:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3528 Description: The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries. Ubuntu-Description: Notes: Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: Patches_linux-source-2.6.15: upstream_linux-source-2.6.15: needed dapper_linux-source-2.6.15: ignored feisty_linux-source-2.6.15: DNE gutsy_linux-source-2.6.15: DNE hardy_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux-source-2.6.20: upstream_linux-source-2.6.20: needed dapper_linux-source-2.6.20: DNE feisty_linux-source-2.6.20: ignored gutsy_linux-source-2.6.20: DNE hardy_linux-source-2.6.20: DNE devel_linux-source-2.6.20: DNE Patches_linux-source-2.6.22: upstream_linux-source-2.6.22: needed dapper_linux-source-2.6.22: DNE feisty_linux-source-2.6.22: DNE gutsy_linux-source-2.6.22: ignored hardy_linux-source-2.6.22: DNE devel_linux-source-2.6.22: DNE Patches_linux: upstream_linux: needed dapper_linux: DNE feisty_linux: DNE gutsy_linux: DNE hardy_linux: ignored devel_linux: not-affected