Candidate: CVE-2008-0600 Description: The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010. References: Ubuntu-Description: Notes: Bugs: upstream: released (2.6.24.2) linux-2.6: released (2.6.24-4) 2.6.18-etch-security: released (2.6.18.dfsg.1-18etch1) 2.6.24-etch-security: released (2.6.24-4) [bugfix/all/stable/2.6.24.2.patch] 2.6.8-sarge-security: N/A 2.4.27-sarge-security: N/A 2.6.15-dapper-security: N/A 2.6.17-edgy-security: released (2.6.17.1-12.44) 2.6.20-feisty-security: released (2.6.20-16.35) 2.6.22-gutsy-security: released (2.6.22-14.52) 2.6.24-hardy-security: N/A