CVE-2009-0834
published 2009-03-06CVE-2009-0834: The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCPIPAN
EPSS
0.44%
35.5th percentile
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | <= 2.6.28.7 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat7.2HIGH
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-04-07·CVSS 4.0
CVE-2009-0029 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
NFS did not correctly handle races between fcntl and interrupts. A local
attacker on an NFS mount could consume unlimited kernel memory, leading to
a denial of service. (CVE-2008-4307)
Sparc syscalls did not correctly check mmap regions. A local attacker could
cause a system panic, leading to a denial of service. (CVE-2008-6107)
In certain situations, cloned processes were able to send signals to parent
processes, crossing privilege boundaries. A local attacker could send
arbitrary signals to parent processes, leading to a denial of service.
(CVE-2009-0028)
The 64-bit syscall interfaces did not correctly handle sign extension. A
local attacker could make malicious syscalls, possibly gaining root
privileges. The
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-04-06·CVSS 4.0
CVE-2008-4307 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
NFS did not correctly handle races between fcntl and interrupts. A local
attacker on an NFS mount could consume unlimited kernel memory, leading to
a denial of service. Ubuntu 8.10 was not affected. (CVE-2008-4307)
Sparc syscalls did not correctly check mmap regions. A local attacker
could cause a system panic, leading to a denial of service. Ubuntu 8.10
was not affected. (CVE-2008-6107)
In certain situations, cloned processes were able to send signals to parent
processes, crossing privilege boundaries. A local attacker could send
arbitrary signals to parent processes, leading to a denial of service.
(CVE-2009-0028)
The kernel keyring did not free memory correctly. A local attacker could
consume unlimited kernel
Red Hat
kernel: x86-64: syscall-audit: 32/64 syscall hole
vendor_redhat·2009-02-27·CVSS 7.2
CVE-2009-0834 [HIGH] kernel: x86-64: syscall-audit: 32/64 syscall hole
kernel: x86-64: syscall-audit: 32/64 syscall hole
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
GHSA
GHSA-3cv7-5j4c-h696: The audit_syscall_entry function in the Linux kernel 2
ghsa_unreviewed·2022-05-02·CVSS 7.2
CVE-2009-0834 [HIGH] GHSA-3cv7-5j4c-h696: The audit_syscall_entry function in the Linux kernel 2
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ccbe495caa5e604b04d5a31d7459a6f6a76a756chttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://marc.info/?l=linux-kernel&m=123579056530191&w=2http://marc.info/?l=linux-kernel&m=123579065130246&w=2http://marc.info/?l=oss-security&m=123597642832637&w=2http://rhn.redhat.com/errata/RHSA-2009-0459.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0473.htmlhttp://scary.beasts.org/security/CESA-2009-001.htmlhttp://secunia.com/advisories/34084http://secunia.com/advisories/34917http://secunia.com/advisories/34962http://secunia.com/advisories/34981http://secunia.com/advisories/35011http://secunia.com/advisories/35015http://secunia.com/advisories/35120http://secunia.com/advisories/35121http://secunia.com/advisories/35185http://secunia.com/advisories/35390http://secunia.com/advisories/35394http://secunia.com/advisories/37471http://wiki.rpath.com/Advisories:rPSA-2009-0084http://www.debian.org/security/2009/dsa-1787http://www.debian.org/security/2009/dsa-1794http://www.debian.org/security/2009/dsa-1800http://www.mandriva.com/security/advisories?name=MDVSA-2009:118http://www.redhat.com/support/errata/RHSA-2009-0451.htmlhttp://www.securityfocus.com/archive/1/503610/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/33951http://www.securitytracker.com/id?1022153http://www.ubuntu.com/usn/usn-751-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://bugzilla.redhat.com/show_bug.cgi?id=487990https://exchange.xforce.ibmcloud.com/vulnerabilities/49061https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9600http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ccbe495caa5e604b04d5a31d7459a6f6a76a756chttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://marc.info/?l=linux-kernel&m=123579056530191&w=2http://marc.info/?l=linux-kernel&m=123579065130246&w=2http://marc.info/?l=oss-security&m=123597642832637&w=2http://rhn.redhat.com/errata/RHSA-2009-0459.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0473.htmlhttp://scary.beasts.org/security/CESA-2009-001.htmlhttp://secunia.com/advisories/34084http://secunia.com/advisories/34917http://secunia.com/advisories/34962http://secunia.com/advisories/34981http://secunia.com/advisories/35011http://secunia.com/advisories/35015http://secunia.com/advisories/35120http://secunia.com/advisories/35121http://secunia.com/advisories/35185http://secunia.com/advisories/35390http://secunia.com/advisories/35394http://secunia.com/advisories/37471http://wiki.rpath.com/Advisories:rPSA-2009-0084http://www.debian.org/security/2009/dsa-1787http://www.debian.org/security/2009/dsa-1794http://www.debian.org/security/2009/dsa-1800http://www.mandriva.com/security/advisories?name=MDVSA-2009:118http://www.redhat.com/support/errata/RHSA-2009-0451.htmlhttp://www.securityfocus.com/archive/1/503610/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/33951http://www.securitytracker.com/id?1022153http://www.ubuntu.com/usn/usn-751-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://bugzilla.redhat.com/show_bug.cgi?id=487990https://exchange.xforce.ibmcloud.com/vulnerabilities/49061https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9600
2009-03-06
Published