4.7
CVE-2009-0859
- EPSS 0.37%
- Veröffentlicht 09.03.2009 21:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:58
- CVE-Watchlists
- Unerledigt
The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_INFO shmctl call, as demonstrated by running the ipcs program.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 2.6.28.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.283 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.7 | 3.4 | 6.9 |
AV:L/AC:M/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html
http://secunia.com/advisories/35390
http://secunia.com/advisories/34981
http://www.debian.org/security/2009/dsa-1787
http://secunia.com/advisories/35011
http://www.debian.org/security/2009/dsa-1794
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html
http://secunia.com/advisories/35394
http://www.ubuntu.com/usn/usn-751-1
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.5
http://secunia.com/advisories/35121
http://www.debian.org/security/2009/dsa-1800
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html
http://secunia.com/advisories/35185
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a68e61e8ff2d46327a37b69056998b47745db6fa
http://marc.info/?l=git-commits-head&m=123387479500599&w=2
http://marc.info/?l=linux-kernel&m=120428209704324&w=2
http://marc.info/?l=linux-kernel&m=123309645625549&w=2
http://openwall.com/lists/oss-security/2009/03/06/1
http://patchwork.kernel.org/patch/6554/
http://www.securityfocus.com/bid/34020
https://exchange.xforce.ibmcloud.com/vulnerabilities/49229