CVE-2009-1895
published 2009-07-16CVE-2009-1895: The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO…
PriorityP422high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.44%
36.1th percentile
The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | <= 2.6.31 | — |
| linux | linux_kernel | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_ubuntu7.8HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-07-28·CVSS 7.8
CVE-2009-1389 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Michael Tokarev discovered that the RTL8169 network driver did not
correctly validate buffer sizes. A remote attacker on the local network
could send specially crafted traffic that would crash the system or
potentially grant elevated privileges. (CVE-2009-1389)
Julien Tinnes and Tavis Ormandy discovered that when executing setuid
processes the kernel did not clear certain personality flags. A local
attacker could exploit this to map the NULL memory page, causing other
vulnerabilities to become exploitable. Ubuntu 6.06 was not affected.
(CVE-2009-1895)
Matt T. Yourst discovered that KVM did not correctly validate the
page table root. A local attacker could exploit this to crash the
system, leading to a denial of s
Red Hat
kernel: personality: fix PER_CLEAR_ON_SETID
vendor_redhat·2009-06-26·CVSS 7.2
CVE-2009-1895 [HIGH] kernel: personality: fix PER_CLEAR_ON_SETID
kernel: personality: fix PER_CLEAR_ON_SETID
The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).
GHSA
GHSA-rgcw-fh34-72mm: The personality subsystem in the Linux kernel before 2
ghsa_unreviewed·2022-05-02
CVE-2009-1895 [HIGH] GHSA-rgcw-fh34-72mm: The personality subsystem in the Linux kernel before 2
The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).
No detection rules found.
No public exploits indexed.
http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f9fabcb58a6d26d6efde842d1703ac7cfa9427b6http://patchwork.kernel.org/patch/32598/http://secunia.com/advisories/35801http://secunia.com/advisories/36045http://secunia.com/advisories/36051http://secunia.com/advisories/36054http://secunia.com/advisories/36116http://secunia.com/advisories/36131http://secunia.com/advisories/36759http://secunia.com/advisories/37471http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1845http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc3http://www.mandriva.com/security/advisories?name=MDVSA-2011:051http://www.osvdb.org/55807http://www.redhat.com/support/errata/RHSA-2009-1193.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1438.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/archive/1/512019/100/0/threadedhttp://www.securityfocus.com/bid/35647http://www.ubuntu.com/usn/usn-807-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1866http://www.vupen.com/english/advisories/2009/3316https://bugs.launchpad.net/bugs/cve/2009-1895https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11768https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7826https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9453https://rhn.redhat.com/errata/RHSA-2009-1540.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1550.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00166.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00223.htmlhttp://blog.cr0.org/2009/06/bypassing-linux-null-pointer.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f9fabcb58a6d26d6efde842d1703ac7cfa9427b6http://patchwork.kernel.org/patch/32598/http://secunia.com/advisories/35801http://secunia.com/advisories/36045http://secunia.com/advisories/36051http://secunia.com/advisories/36054http://secunia.com/advisories/36116http://secunia.com/advisories/36131http://secunia.com/advisories/36759http://secunia.com/advisories/37471http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1845http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc3http://www.mandriva.com/security/advisories?name=MDVSA-2011:051http://www.osvdb.org/55807http://www.redhat.com/support/errata/RHSA-2009-1193.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1438.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/archive/1/512019/100/0/threadedhttp://www.securityfocus.com/bid/35647http://www.ubuntu.com/usn/usn-807-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1866http://www.vupen.com/english/advisories/2009/3316https://bugs.launchpad.net/bugs/cve/2009-1895https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11768https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7826https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9453https://rhn.redhat.com/errata/RHSA-2009-1540.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1550.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00166.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00223.html
2009-07-16
Published