CVE-2005-2800

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 06 Sept 2005, 04:00
Last modified:07 Aug 2024, 22:45

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
2.1 LOW
v2.0 (nvd)
EPSS Score
0.21% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

06 Sept 2005, 04:00
Published
Vulnerability first disclosed
07 Aug 2024, 22:45
Last Modified
Vulnerability information updated

Description

Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.

CVSS Metrics

  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.21% Percentile: 43%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • linuxlinux_kernel

    2.6.0 | 2.6.1 | 2.6.2 | 2.6.3 | 2.6.4 | 2.6.5 | 2.6.6 | 2.6.7 | 2.6.8 | 2.6.9:2.6.20 | 2.6.10 | 2.6.11 | 2.6.12 | 2.6.13

References (14)