CVE-2005-2800

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 06 Sept 2005, 04:00
Last modified:07 Aug 2024, 22:45

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
2.1 LOW
v2.0 (nvd)
EPSS Score
0.83% LOW
1% probability +0.62%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

06 Sept 2005, 04:00
Published
Vulnerability first disclosed
07 Aug 2024, 22:45
Last Modified
Vulnerability information updated

Description

Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.

CVSS Metrics

  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.83% Percentile: 53%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • linuxlinux kernel

    2.6.0 | 2.6.1 | 2.6.2 | 2.6.3 | 2.6.4 | 2.6.5 | 2.6.6 | 2.6.7 | 2.6.8 | 2.6.9:2.6.20 | 2.6.10 | 2.6.11 | 2.6.12 | 2.6.13

References (14)