CVE-2009-0935
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device's event list mutex to be unlocked twice and prevents proper synchronization of a data structure for the inotify instance.
La función inotify_read en el kernel de Linux versiones 2.6.27 hasta 2.6.27.13, 2.6.28 hasta 2.6.28.2 y 2.6.29-rc3, permite a los usuarios locales causar una denegación de servicio (OOPS) por medio de una lectura con una dirección no válida en una instancia inotify, lo que causa que la exclusión mutua de la lista de eventos del dispositivo se desbloquee dos veces e impida la sincronización apropiada de una estructura de datos para la instancia inotify.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-03-17 CVE Reserved
- 2009-03-18 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-667: Improper Locking
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.3 | Broken Link | |
http://www.openwall.com/lists/oss-security/2009/03/18/5 | Mailing List | |
http://www.openwall.com/lists/oss-security/2009/03/19/2 | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/49331 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://marc.info/?l=linux-kernel&m=123337123501681&w=2 | 2024-02-09 | |
http://www.openwall.com/lists/oss-security/2009/03/06/2 | 2024-02-09 | |
http://www.securityfocus.com/bid/33624 | 2024-02-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=488935 | 2024-02-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 2.6.27 <= 2.6.27.13 Search vendor "Linux" for product "Linux Kernel" and version " >= 2.6.27 <= 2.6.27.13" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 2.6.28 <= 2.6.28.2 Search vendor "Linux" for product "Linux Kernel" and version " >= 2.6.28 <= 2.6.28.2" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.29 Search vendor "Linux" for product "Linux Kernel" and version "2.6.29" | rc3 |
Affected
|