VDB
CVE-2009-0835
CVE-2009-0835
PUBLISHED
CVSS 3.5999999046325684 LOW
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.
EPSS 0.93% · 57.2th percentile
Risk Scores
CVSS 2.0
3.5999999046325684
EPSS Score
0.93%
57.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linux | linux_kernel | 2.6.25.12, 2.6.25, 2.6.25.1 |
| n/a | n/a | * |
Timeline
- Mar 2, 2009 PoC Published
- Mar 6, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- 35390 third-party-advisory
- 34786 third-party-advisory
- SUSE-SA:2009:028 vendor-advisory
- http://scary.beasts.org/security/CESA-2009-001.html url
- USN-751-1 vendor-advisory
- 35185 third-party-advisory
- 34084 third-party-advisory
- 34917 third-party-advisory
- [linux-kernel] 20090228 [PATCH 2/2] x86-64: seccomp: fix 32/64 syscall hole mailing-list
- http://scary.beasts.org/security/CESA-2009-004.html url
- https://bugzilla.redhat.com/show_bug.cgi?id=487255 url
- RHSA-2009:0451 vendor-advisory
- 35121 third-party-advisory
- 35394 third-party-advisory
- http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-seccomp.html url
- MDVSA-2009:118 vendor-advisory
- [oss-security] 20090302 CVE request: kernel: x86-64: seccomp: 32/64 syscall hole mailing-list
- SUSE-SA:2009:030 vendor-advisory
- 33948 vdb
- [linux-kernel] 20090227 Re: [PATCH 2/2] x86-64: seccomp: fix 32/64 syscall hole mailing-list
…and 5 more