CVE-2009-0835
Linux Kernel 2.6.x - 'seccomp' System Call Security Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.
La función __secure_computing en kernel/seccomp.c en el subsistema seccomp en el núcleo de Linux v2.6.28.7 y versiones anteriores en la plataforma x86_64, cuando CONFIG_SECCOMP está activo, no maneja adecuadamente (1) un proceso de 32-bit haciendo una llamada al sistema (syscall) de 64-bit o (2) un proceso de 64-bit haciendo una llamada al sistema (syscall) de 32-bit, lo cual permite a usuarios locales evitar restricciones de acceso a través de llamadas al sistema (syscalls) manipuladsa que son malinterpretadas como (a) stat o (b) chmod, una cuestión distinta que CVE-2009-0342 y CVE-2009-0343.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-03-02 First Exploit
- 2009-03-06 CVE Reserved
- 2009-03-06 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (26)
URL | Tag | Source |
---|---|---|
http://lkml.org/lkml/2009/2/28/23 | Mailing List | |
http://marc.info/?l=linux-kernel&m=123579056530191&w=2 | Mailing List | |
http://marc.info/?l=oss-security&m=123597627132485&w=2 | Mailing List | |
http://scary.beasts.org/security/CESA-2009-004.html | X_refsource_misc | |
http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-seccomp.html | X_refsource_misc | |
http://secunia.com/advisories/34786 | Third Party Advisory | |
http://www.securityfocus.com/bid/33948 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32829 | 2009-03-02 | |
http://marc.info/?l=linux-kernel&m=123579069630311&w=2 | 2024-08-07 | |
http://scary.beasts.org/security/CESA-2009-001.html | 2024-08-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=487255 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html | 2012-03-19 | |
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html | 2012-03-19 | |
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html | 2012-03-19 | |
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html | 2012-03-19 | |
http://secunia.com/advisories/34084 | 2012-03-19 | |
http://secunia.com/advisories/34917 | 2012-03-19 | |
http://secunia.com/advisories/35121 | 2012-03-19 | |
http://secunia.com/advisories/35185 | 2012-03-19 | |
http://secunia.com/advisories/35390 | 2012-03-19 | |
http://secunia.com/advisories/35394 | 2012-03-19 | |
http://www.debian.org/security/2009/dsa-1800 | 2012-03-19 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2009:118 | 2012-03-19 | |
http://www.redhat.com/support/errata/RHSA-2009-0451.html | 2012-03-19 | |
http://www.ubuntu.com/usn/usn-751-1 | 2012-03-19 | |
https://access.redhat.com/security/cve/CVE-2009-0835 | 2009-04-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.1 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.1" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.2 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.2" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.3 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.3" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.4 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.4" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.5 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.5" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.6 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.6" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.7 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.7" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.8 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.8" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.9 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.9" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.10 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.10" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.11 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.11" | x86_64 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.25.12 Search vendor "Linux" for product "Linux Kernel" and version "2.6.25.12" | x86_64 |
Affected
|