cbcvebase.
CVE-2009-1961
published 2009-06-08

CVE-2009-1961: The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly…

medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EXPLOIT
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
linuxlinux_kernel<= 2.6.19
linuxlinux_kernel
linuxlinux_kernel>= 2.6.27 < 2.6.27.242.6.27.24
linuxlinux_kernel>= 2.6.29 < 2.6.29.42.6.29.4
opensuseopensuse
opensuseopensuse
suselinux_enterprise
suselinux_enterprise_desktop
suselinux_enterprise_server