PT-2009-6113 · Linux+1 · Linux Kernel+1

Bryn M. Reeves

·

Published

2009-11-16

·

Updated

2023-02-13

·

CVE-2009-3889

CVSS v2.0

6.6

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.27
Description The issue concerns the megaraid sas driver in the Linux kernel, where the dbg lvl file has world-writable permissions. This allows local users to modify the file, which in turn enables them to change the behavior and logging level of the driver.
Recommendations For Linux kernel versions prior to 2.6.27, update to version 2.6.27 or later to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2009-3889
DSA-2005-1
RHSA-2009:1635
RHSA-2010:0046
RHSA-2010:0076
RHSA-2010_0046
RHSA-2010_0076

Affected Products

Linux Kernel
Red Hat