7.2
CVE-2009-2584
- EPSS 0.52%
- Veröffentlicht 23.07.2009 20:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:45
- CVE-Watchlists
- Unerledigt
Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain privileges via a crafted count argument, which triggers a stack-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 2.6.30.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.4 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://grsecurity.net/~spender/exploit_demo.c
http://lkml.org/lkml/2009/7/20/348
http://lkml.org/lkml/2009/7/20/362
http://secunia.com/advisories/37105
http://www.securityfocus.com/bid/35753
http://www.ubuntu.com/usn/USN-852-1
http://xorl.wordpress.com/2009/07/21/linux-kernel-sgi-gru-driver-off-by-one-overwrite/
https://exchange.xforce.ibmcloud.com/vulnerabilities/51887