CVE-2009-3547

HIGH EXPLOITED

Linux Kernel < 2.6.31.14 - Race Condition

Title source: rule

Description

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Earl Chew · bashlocallinux
https://www.exploit-db.com/exploits/10018
exploitdb WORKING POC VERIFIED
by Matthew Bergin · pythonlocallinux
https://www.exploit-db.com/exploits/9844
exploitdb WORKING POC VERIFIED
by teach & xipe · clocallinux
https://www.exploit-db.com/exploits/33322
exploitdb WORKING POC VERIFIED
by teach & xipe · clocallinux
https://www.exploit-db.com/exploits/33321
exploitdb WORKING POC
by spender · clocallinux
https://www.exploit-db.com/exploits/40812

References (29)

... and 9 more

Scores

CVSS v3 7.0
EPSS 0.0315
EPSS Percentile 86.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-02-09
CWE
CWE-362 CWE-476 CWE-672
Status published
Products (27)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
canonical/ubuntu_linux 9.04
canonical/ubuntu_linux 9.10
fedoraproject/fedora 10
linux/linux_kernel 2.6.32 (6 CPE variants)
linux/linux_kernel < 2.6.31.14
novell/linux_desktop 9
opensuse/opensuse 11.0
... and 17 more
Published Nov 04, 2009
Tracked Since Feb 18, 2026