CVE-2004-2607 PUBLISHED CVSS 2.0999999046325684 LOW

A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.

EPSS 0.06% · 19.8th percentile

Risk Scores

CVSS v2.0
2.0999999046325684
EPSS Score
0.06%
19.8th percentile

Affected Products

VendorProductVersions
linuxlinux_kernel2.6.5, 2.4.0, 2.4.0
n/an/an/a

Timeline

References

Open in Interactive Console →