4.9
CVE-2009-0748
- EPSS 0.51%
- Veröffentlicht 27.02.2009 17:30:09
- Zuletzt bearbeitet 16.06.2026 23:05:43
- CVE-Watchlists
- Unerledigt
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate the superblock configuration, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) by attempting to mount a crafted ext4 filesystem.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version2.6.27
Linux ≫ Linux Kernel Version2.6.27 Updaterc1
Linux ≫ Linux Kernel Version2.6.27 Updaterc2
Linux ≫ Linux Kernel Version2.6.27 Updaterc3
Linux ≫ Linux Kernel Version2.6.27 Updaterc4
Linux ≫ Linux Kernel Version2.6.27 Updaterc5
Linux ≫ Linux Kernel Version2.6.27 Updaterc6
Linux ≫ Linux Kernel Version2.6.27 Updaterc7
Linux ≫ Linux Kernel Version2.6.27 Updaterc8
Linux ≫ Linux Kernel Version2.6.27 Updaterc9
Linux ≫ Linux Kernel Version2.6.27.1
Linux ≫ Linux Kernel Version2.6.27.2
Linux ≫ Linux Kernel Version2.6.27.3
Linux ≫ Linux Kernel Version2.6.27.4
Linux ≫ Linux Kernel Version2.6.27.5
Linux ≫ Linux Kernel Version2.6.27.6
Linux ≫ Linux Kernel Version2.6.27.7
Linux ≫ Linux Kernel Version2.6.27.8
Linux ≫ Linux Kernel Version2.6.27.9
Linux ≫ Linux Kernel Version2.6.27.10
Linux ≫ Linux Kernel Version2.6.27.11
Linux ≫ Linux Kernel Version2.6.27.12
Linux ≫ Linux Kernel Version2.6.27.13
Linux ≫ Linux Kernel Version2.6.27.14
Linux ≫ Linux Kernel Version2.6.27.15
Linux ≫ Linux Kernel Version2.6.27.16
Linux ≫ Linux Kernel Version2.6.27.17
Linux ≫ Linux Kernel Version2.6.27.18
Linux ≫ Linux Kernel Version2.6.28
Linux ≫ Linux Kernel Version2.6.28 Updaterc1
Linux ≫ Linux Kernel Version2.6.28 Updaterc2
Linux ≫ Linux Kernel Version2.6.28 Updaterc3
Linux ≫ Linux Kernel Version2.6.28 Updaterc4
Linux ≫ Linux Kernel Version2.6.28 Updaterc5
Linux ≫ Linux Kernel Version2.6.28 Updaterc6
Linux ≫ Linux Kernel Version2.6.28 Updaterc7
Linux ≫ Linux Kernel Version2.6.28.1
Linux ≫ Linux Kernel Version2.6.28.2
Linux ≫ Linux Kernel Version2.6.28.3
Linux ≫ Linux Kernel Version2.6.28.4
Linux ≫ Linux Kernel Version2.6.28.5
Linux ≫ Linux Kernel Version2.6.28.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.395 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://secunia.com/advisories/37471
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/3316
http://secunia.com/advisories/34394
http://www.debian.org/security/2009/dsa-1749
http://www.ubuntu.com/usn/usn-751-1
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7
http://rhn.redhat.com/errata/RHSA-2009-1243.html
http://secunia.com/advisories/36562
http://www.vupen.com/english/advisories/2009/0509
http://bugzilla.kernel.org/show_bug.cgi?id=12371
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4ec110281379826c5cf6ed14735e47027c3c5765
http://osvdb.org/52203
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10683
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8526