CVE-2009-0935

MEDIUM

Linux Kernel 2.6.27-2.6.27.13, 2.6.28-2.6.28.2, 2.6.29-rc3 - Denial of Service via inotify_read Function

Title source: llm
STIX 2.1

Description

The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device's event list mutex to be unlocked twice and prevents proper synchronization of a data structure for the inotify instance.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49331
Broken Link, Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33624
Mailing List, Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/03/06/2
Mailing List, Patch mailing-list x_refsource_mlist
http://marc.info/?l=linux-kernel&m=123337123501681&w=2
Issue Tracking, Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=488935
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/03/19/2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/03/18/5

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 18.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-667
Status published
Products (2)
linux/linux_kernel 2.6.29 rc3
linux/linux_kernel 2.6.27 - 2.6.27.13
Published Mar 18, 2009
Tracked Since Feb 18, 2026