cbcvebase.
CVE-2009-1961
published 2009-06-08

CVE-2009-1961: The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly…

PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EXPLOIT
EPSS
0.59%
44.6th percentile
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
linuxlinux_kernel<= 2.6.19
linuxlinux_kernel
linuxlinux_kernel>= 2.6.27 < 2.6.27.242.6.27.24
linuxlinux_kernel>= 2.6.29 < 2.6.29.42.6.29.4
opensuseopensuse
opensuseopensuse
suselinux_enterprise
suselinux_enterprise_desktop
suselinux_enterprise_server

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
vendor_ubuntu4.9MEDIUM
vendor_redhat4.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.