CVE-2009-0028
- EPSS 0.7%
- Veröffentlicht 27.02.2009 17:30:09
- Zuletzt bearbeitet 16.06.2026 23:04:07
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting thi...
CVE-2009-0745
- EPSS 0.41%
- Veröffentlicht 27.02.2009 17:30:09
- Zuletzt bearbeitet 16.06.2026 23:05:42
The ext4_group_add function in fs/ext4/resize.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not properly initialize the group descriptor during a resize (aka resize2fs) operation, which might allow local users to cause...
CVE-2009-0746
- EPSS 0.75%
- Veröffentlicht 27.02.2009 17:30:09
- Zuletzt bearbeitet 16.06.2026 23:05:43
The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a c...
CVE-2009-0747
- EPSS 0.41%
- Veröffentlicht 27.02.2009 17:30:09
- Zuletzt bearbeitet 16.06.2026 23:05:43
The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of servic...
CVE-2009-0748
- EPSS 0.51%
- Veröffentlicht 27.02.2009 17:30:09
- Zuletzt bearbeitet 16.06.2026 23:05:43
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate the superblock configuration, which allows local users to cause a denial of service (NULL pointer dereference and...
CVE-2009-0675
- EPSS 0.4%
- Veröffentlicht 22.02.2009 22:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:32
The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset t...
CVE-2009-0676
- EPSS 0.7%
- Veröffentlicht 22.02.2009 22:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:32
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt...
CVE-2009-0605
- EPSS 0.37%
- Veröffentlicht 17.02.2009 17:30:05
- Zuletzt bearbeitet 16.06.2026 23:05:24
Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trig...
CVE-2008-6107
- EPSS 0.39%
- Veröffentlicht 10.02.2009 22:00:07
- Zuletzt bearbeitet 16.06.2026 23:01:37
The (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, the (2) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c, and the (3) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel before 2.6.25.4, o...
CVE-2009-0322
- EPSS 0.5%
- Veröffentlicht 28.01.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:04:45
drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size...