Lucene search

K
cve[email protected]CVE-2009-2908
HistoryOct 13, 2009 - 10:30 a.m.

CVE-2009-2908

2009-10-1310:30:00
web.nvd.nist.gov
59
cve-2009-2908
linux kernel
ecryptfs
denial of service
kernel oops
arbitrary code
null pointer dereference

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a β€œnegative dentry” and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount.

Affected configurations

NVD
Node
linuxlinux_kernelMatch2.6.31

References

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%