CVE-2009-1961

The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.19
linuxlinux_kernel
2.6.27 ≤
𝑥
< 2.6.27.24
linuxlinux_kernel
2.6.29 ≤
𝑥
< 2.6.29.4
linuxlinux_kernel
2.6.30:rc1
linuxlinux_kernel
2.6.30:rc2
debiandebian_linux
4.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
opensuseopensuse
10.3
opensuseopensuse
11.1
suselinux_enterprise
11.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
jaunty
Fixed 2.6.28-13.45
released
intrepid
Fixed 2.6.27-14.35
released
hardy
Fixed 2.6.24-24.55
released
dapper
dne
linux-source-2.6.15
jaunty
dne
intrepid
dne
hardy
dne
dapper
Fixed 2.6.15-54.77
released
References