CVE-2009-3547

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.31.14
linuxlinux_kernel
2.6.32
linuxlinux_kernel
2.6.32:rc1
linuxlinux_kernel
2.6.32:rc2
linuxlinux_kernel
2.6.32:rc3
linuxlinux_kernel
2.6.32:rc4
linuxlinux_kernel
2.6.32:rc5
opensuseopensuse
11.0
opensuseopensuse
11.2
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
canonicalubuntu_linux
9.10
vmwarevma
4.0
vmwareesx
4.0
redhatmrg_realtime
1.0
redhatenterprise_linux_desktop
3.0
redhatenterprise_linux_desktop
4.0
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_eus
4.8
redhatenterprise_linux_eus
5.4
redhatenterprise_linux_server
3.0
redhatenterprise_linux_server
4.0
redhatenterprise_linux_server
5.0
redhatenterprise_linux_workstation
3.0
redhatenterprise_linux_workstation
4.0
redhatenterprise_linux_workstation
5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
karmic
Fixed 2.6.31-16.52
released
jaunty
Fixed 2.6.28-17.58
released
intrepid
Fixed 2.6.27-16.44
released
hardy
Fixed 2.6.24-26.64
released
dapper
dne
linux-source-2.6.15
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
Fixed 2.6.15-55.81
released
References