← Back

CVE-2009-2848

nvd nist
Published: Aug 18, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.9
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:C
Exploitability: 3.4 / Impact: 8.5
Source: NVD

Description

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.

Affected (26)

Products: Linux: Linux Kernel · Novell: Linux Desktop · Opensuse: Opensuse · +5 more
Show all products
1 product
Linux Kernel
1 product
Linux Desktop
1 product
Opensuse
2 products
Linux Enterprise Desktop
Linux Enterprise Server
1 product
Fedora
1 product
Ubuntu Linux
3 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
2 products
Esx
Vma
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Up to 2.6.29.5
Version 2.6.30
Version 2.6.30 rc1
Version 2.6.30 rc2
Version 2.6.30 rc3
Version 2.6.30 rc4
Version 2.6.30 rc5
Version 2.6.30 rc6
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 9
Version 11.0
Version 10 sp2
Suse
Version 10 sp2
Version 9
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 6.06
Version 8.04
Version 8.10
Version 9.04
Configuration E
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.0
Version 5.0
Redhat
Version 3.0
Version 5.0
Redhat
Version 3.0
Version 5.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 4.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 5.0

References (52)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.