CVE-2009-3939

The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.31.6
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_eus
5.4
redhatenterprise_linux_server
5.0
redhatenterprise_linux_workstation
5.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
canonicalubuntu_linux
9.10
debiandebian_linux
5.0
avayaaura_application_enablement_services
5.2
avayaaura_application_enablement_services
5.2.1
avayaaura_communication_manager
5.2
avayaaura_session_manager
1.1
avayaaura_session_manager
5.2
avayaaura_sip_enablement_services
5.2
avayaaura_system_manager
5.2
avayaaura_system_manager
6.0
avayaaura_system_platform
1.1
avayavoice_portal
5.0
opensuseopensuse
11.0
opensuseopensuse
11.1
opensuseopensuse
11.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
karmic
Fixed 2.6.31-16.52
released
jaunty
Fixed 2.6.28-17.58
released
intrepid
Fixed 2.6.27-16.44
released
hardy
not-affected
dapper
dne
linux-source-2.6.15
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
not-affected
References