4.7

CVE-2009-0859

The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_INFO shmctl call, as demonstrated by running the ipcs program.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 2.6.28.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.283
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html
http://secunia.com/advisories/35390
http://secunia.com/advisories/34981
http://www.debian.org/security/2009/dsa-1787
http://secunia.com/advisories/35011
http://www.debian.org/security/2009/dsa-1794
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html
http://secunia.com/advisories/35394
http://www.ubuntu.com/usn/usn-751-1
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.5
http://secunia.com/advisories/35121
http://www.debian.org/security/2009/dsa-1800
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html
http://secunia.com/advisories/35185
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a68e61e8ff2d46327a37b69056998b47745db6fa
http://marc.info/?l=git-commits-head&m=123387479500599&w=2
http://marc.info/?l=linux-kernel&m=120428209704324&w=2
http://marc.info/?l=linux-kernel&m=123309645625549&w=2
http://openwall.com/lists/oss-security/2009/03/06/1
http://patchwork.kernel.org/patch/6554/
http://www.securityfocus.com/bid/34020
https://exchange.xforce.ibmcloud.com/vulnerabilities/49229