PT-2009-3521 · Linux · Linux Kernel
Eugene Teo
·
Published
2009-03-18
·
Updated
2024-02-09
·
CVE-2009-0935
CVSS v2.0
4.7
Medium
| Vector | AV:L/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.6.27 through 2.6.27.13
Linux kernel versions 2.6.28 through 2.6.28.2
Linux kernel version 2.6.29-rc3
Description
The issue allows local users to cause a denial of service via a read with an invalid address to an inotify instance. This causes the device's event list mutex to be unlocked twice, preventing proper synchronization of a data structure for the inotify instance.
Recommendations
For Linux kernel versions 2.6.27 through 2.6.27.13, update to a version outside of this range to resolve the issue.
For Linux kernel versions 2.6.28 through 2.6.28.2, update to a version outside of this range to resolve the issue.
For Linux kernel version 2.6.29-rc3, update to a newer version to resolve the issue.
As a temporary workaround, consider restricting access to the inotify instance to minimize the risk of exploitation.
Fix
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel