4.7

CVE-2009-1961

Exploit

The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 2.6.19
LinuxLinux Kernel Version >= 2.6.27 < 2.6.27.24
LinuxLinux Kernel Version >= 2.6.29 < 2.6.29.4
LinuxLinux Kernel Version2.6.30 Updaterc1
LinuxLinux Kernel Version2.6.30 Updaterc2
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
OpensuseOpensuse Version10.3
OpensuseOpensuse Version11.1
SuseLinux Enterprise Version11.0 Update-
SuseLinux Enterprise Desktop Version11 Update-
SuseLinux Enterprise Server Version11 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.13% 0.296
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:N/I:N/A:P
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

http://securitytracker.com/id?1022307
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/35143
Third Party Advisory
Exploit
Broken Link
VDB Entry