CVE-2009-4131

Linux kernel <2.6.32 - Local Privilege Escalation

Title source: llm

Description

The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Akira Fujita · textlocallinux
https://www.exploit-db.com/exploits/33395

Scores

EPSS 0.0008
EPSS Percentile 24.3%

Classification

CWE
CWE-264
Status draft

Affected Products (50)

linux/linux_kernel < 2.6.32
linux/linux_kernel < 2.6.32
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Dec 13, 2009
Tracked Since Feb 18, 2026