Buffer overflow in the (1) sysfs_show_available_clocksources and (2) sysfs_show_current_clocksources functions in Linux kernel 2.6.23 and earlier might allow local users to cause a denial of service or execute arbitrary code via crafted clock source names.  NOTE: follow-on analysis by Linux developers states that "There is no way for unprivileged users (or really even the root user) to add new clocksources.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.cve.org/CVERecord?id=CVE-2007-5908 | 
                    
                    
                     | 
            
History
                    Wed, 28 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
Thu, 22 May 2025 04:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
Status: REJECTED
Assigner: mitre
Published: 2007-11-09T19:00:00
Updated: 2007-11-28T10:00:00
Reserved: 2007-11-09T00:00:00
Link: CVE-2007-5908
No data.
Status : Rejected
Published: 2007-11-09T19:46:00.000
Modified: 2023-11-07T02:01:24.240
Link: CVE-2007-5908