AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2008-5396

HIGH · CVSS 7.2 EPSS 0.35%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-12-09 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2008-5396
Severity
HIGH
CVSS
7.2
EPSS
0.35%

Original Filing — NVD Description

Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to missing validation of the sync field associated with the ZT_SPANCONFIG ioctl.