CVE-2005-2800
Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.
- Affected products
- Debian, Red Hat, Suse Linux Enterprise
- Linux Linux Kernel
- = 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.9, 2.6.10, 2.6.11, 2.6.12, 2.6.13
- CVSS 2.0
- 2.1 LOW
- EPSS
- 0.8% (55th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2005-09-06
CVE-2005-2800 at NVD
2 known exploits for CVE-2005-2800
Proof-of-concept code and exploit modules indexed by Sploitus