PT-2009-6762 · Opensuse+2 · Opensuse+2

Bryn M. Reeves

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-3939

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.31.6 and earlier openSUSE kernel-ps3-debuginfo (affected versions not specified) openSUSE kernel-ps3-debugsource (affected versions not specified)
Description The issue affects the Linux kernel and openSUSE operating system, allowing for potential disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. Specifically, the poll mode io file for the megaraid sas driver has world-writable permissions, enabling local users to modify the I/O mode of the driver by changing this file.
Recommendations For Linux kernel versions 2.6.31.6 and earlier, consider restricting access to the poll mode io file to prevent local users from modifying it. For openSUSE kernel-ps3-debuginfo and kernel-ps3-debugsource, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05250
BDU:2015-05251
CVE-2009-3939
DSA-1996-1
OPENSUSE-SU-2024:10128-1
RHSA-2009:1635
RHSA-2010:0046
RHSA-2010:0076
RHSA-2010_0046
RHSA-2010_0076

Affected Products

Linux Kernel
Red Hat
Opensuse