PT-2009-5550 · Linux · Linux Kernel

Marcus Meissner

+1

·

Published

2009-09-17

·

Updated

2012-03-19

·

CVE-2009-3234

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel version 2.6.31-rc1
Description The issue is related to a buffer overflow in the perf copy attr function, which can be triggered by providing "big size data" to the perf counter open system call. This can cause a denial of service (crash) and potentially allow the execution of arbitrary code.
Recommendations For Linux kernel version 2.6.31-rc1, consider applying a patch to fix the buffer overflow issue in the perf copy attr function. As a temporary workaround, restrict access to the perf counter open system call to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3234

Affected Products

Linux Kernel