Buffer overflow in the (1) sysfs_show_available_clocksources and (2) sysfs_show_current_clocksources functions in Linux kernel 2.6.23 and earlier might allow local users to cause a denial of service or execute arbitrary code via crafted clock source names. NOTE: follow-on analysis by Linux developers states that "There is no way for unprivileged users (or really even the root user) to add new clocksources.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cve.org/CVERecord?id=CVE-2007-5908 |
![]() |
History
Wed, 28 May 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
Thu, 22 May 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |

Status: REJECTED
Assigner: mitre
Published: 2007-11-09T19:00:00
Updated: 2007-11-28T10:00:00
Reserved: 2007-11-09T00:00:00
Link: CVE-2007-5908

No data.

Status : Rejected
Published: 2007-11-09T19:46:00.000
Modified: 2023-11-07T02:01:24.240
Link: CVE-2007-5908
