CVE-2009-2848

Linux Kernel < 2.6.29.5 - Improper Privilege Management

Title source: rule

Description

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.

References (26)

... and 6 more

Scores

EPSS 0.0007
EPSS Percentile 22.0%

Classification

CWE
CWE-269
Status draft

Affected Products (26)

linux/linux_kernel < 2.6.29.5
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
novell/linux_desktop
opensuse/opensuse
suse/linux_enterprise_desktop
suse/linux_enterprise_server
suse/linux_enterprise_server
fedoraproject/fedora
canonical/ubuntu_linux
... and 11 more

Timeline

Published Aug 18, 2009
Tracked Since Feb 18, 2026