VDB
CVE-2009-1961
CVE-2009-1961
PUBLISHED
CVSS 1.899999976158142 LOW
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
EPSS 0.11% · 28.5th percentile
Risk Scores
CVSS v2.0
1.899999976158142
EPSS Score
0.11%
28.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| canonical | ubuntu_linux | 8.04, 8.10, 9.04 |
| n/a | n/a | n/a |
| linux | linux_kernel | 0, 2.6.30, 2.6.29 |
| opensuse | opensuse | 11.1, 10.3 |
| debian | debian_linux | 4.0 |
| suse | linux_enterprise | 11.0 |
| suse | linux_enterprise_server | 11 |
| suse | linux_enterprise_desktop | 11 |
Timeline
- May 29, 2009 PoC Published
- Jun 6, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 17, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 1, 2023 EPSS Score
References
- 35390 third-party-advisory
- MDVSA-2009:135 vendor-advisory
- MDVSA-2009:148 vendor-advisory
- 35656 third-party-advisory
- DSA-1844 vendor-advisory
- 1022307 vdb
- [oss-security] 20090602 Re: CVE request: kernel: splice local denial of service mailing-list
- RHSA-2009:1157 vendor-advisory
- SUSE-SA:2009:030 vendor-advisory
- 36051 third-party-advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=7bfac9ecf0585962fe13584f5cf526d8c8e76f17 url
- SUSE-SA:2009:031 vendor-advisory
- USN-793-1 vendor-advisory
- [oss-security] 20090530 Re: CVE request: kernel: splice local denial of service mailing-list
- 35143 vdb
- [oss-security] 20090603 Re: CVE request: kernel: splice local denial of service mailing-list
- [oss-security] 20090529 CVE request: kernel: splice local denial of service mailing-list
- SUSE-SA:2009:038 vendor-advisory
- 35394 third-party-advisory
- 35847 third-party-advisory
…and 2 more