CVE-2009-1527

Linux Kernel < 2.6.29 - Race Condition

Title source: rule

Description

Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to locking an incorrect cred_exec_mutex object.

Exploits (1)

exploitdb WORKING POC VERIFIED
by s0m3b0dy · clocallinux
https://www.exploit-db.com/exploits/8673

Scores

EPSS 0.0006
EPSS Percentile 18.7%

Classification

CWE
CWE-362
Status draft

Affected Products (5)

linux/linux_kernel < 2.6.29
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel

Timeline

Published May 05, 2009
Tracked Since Feb 18, 2026