CVE-2009-2857

MEDIUM

OpenSolaris < snv_103 and Solaris 8-10 - Denial of Service via mmap and Write Deadlock

Title source: llm
STIX 2.1

Description

The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.

References (5)

Core 5
Core References
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2291
Broken Link, Patch, Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-257848-1
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36319

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 17.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-667
Status published
Products (4)
oracle/opensolaris < snv_103
oracle/solaris 8
oracle/solaris 9
oracle/solaris 10
Published Aug 19, 2009
Tracked Since Feb 18, 2026