PT-2010-1326 · Linux+1 · Linux Kernel+1

Tavis Ormandy

·

Published

2010-01-19

·

Updated

2023-02-13

·

CVE-2009-4141

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.33-rc4-git1
Description The issue is related to a use-after-free vulnerability in the fasync helper function, located in fs/fcntl.c. This vulnerability can be exploited by local users to gain privileges. The exploitation vectors include enabling O ASYNC (also known as FASYNC or FIOASYNC) on a locked file and then closing the file.
Recommendations For Linux kernel versions prior to 2.6.33-rc4-git1, update to version 2.6.33-rc4-git1 or later to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2009-4141
RHSA-2010:0046
RHSA-2010:0149
RHSA-2010:0161
RHSA-2010_0046

Affected Products

Linux Kernel
Red Hat