CVE-2009-3547
HIGH EXPLOITEDLinux Kernel < 2.6.32-rc6 - Race Condition in Pipe Handling via /proc/*/fd/ Pathname
Title source: llmExploitation Summary
CVE-2009-3547 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 5 public exploits from researchers including Earl Chew, Matthew Bergin, teach & xipe.
AI-analyzed exploit summary This exploit targets a race condition in the Linux kernel (CVE-2009-3547) by manipulating file descriptors in /proc. It repeatedly spawns a process with a pipe, then attempts to write to the process's fd/1 to trigger the vulnerability.
Description
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.
Exploits (5)
This exploit targets a race condition in the Linux kernel (CVE-2009-3547) by manipulating file descriptors in /proc. It repeatedly spawns a process with a pipe, then attempts to write to the process's fd/1 to trigger the vulnerability.
This exploit targets a race condition in the Linux kernel's pipe.c to achieve local privilege escalation. It attempts to manipulate file descriptors of a process to trigger the vulnerability.
This exploit targets a NULL-pointer dereference vulnerability in the Linux kernel's pipe.c (CVE-2009-3547) to achieve local privilege escalation. It manipulates kernel memory structures to overwrite credentials and spawn a root shell.
This exploit targets a NULL-pointer dereference vulnerability in the Linux kernel's pipe implementation (CVE-2009-3547) to achieve local privilege escalation. It maps kernel structures to NULL, manipulates pipe buffers, and escalates privileges by overwriting kernel memory.
This exploit targets a null pointer dereference vulnerability in the Linux kernel (CVE-2009-3547) to achieve local privilege escalation. It manipulates pipe operations and spinlocks to gain root access on vulnerable systems.
References (29)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H