CVE-2009-3939
published 2009-11-16CVE-2009-3939: The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change…
PriorityP423high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.44%
36.3th percentile
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | aura_application_enablement_services | — | — |
| avaya | aura_application_enablement_services | — | — |
| avaya | aura_communication_manager | — | — |
| avaya | aura_session_manager | — | — |
| avaya | aura_session_manager | — | — |
| avaya | aura_sip_enablement_services | — | — |
| avaya | aura_system_manager | — | — |
| avaya | aura_system_manager | — | — |
| avaya | aura_system_platform | — | — |
| avaya | voice_portal | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | <= 2.6.31.6 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.6MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:C
vendor_redhat7.1HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-12-05·CVSS 4.9
CVE-2009-3726 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the AX.25 network subsystem did not correctly
check integer signedness in certain setsockopt calls. A local attacker
could exploit this to crash the system, leading to a denial of service.
Ubuntu 9.10 was not affected. (CVE-2009-2909)
Jan Beulich discovered that the kernel could leak register contents to
32-bit processes that were switched to 64-bit mode. A local attacker
could run a specially crafted binary to read register values from an
earlier process, leading to a loss of privacy. (CVE-2009-2910)
Dave Jones discovered that the gdth SCSI driver did not correctly validate
array indexes in certain ioctl calls. A local attacker could exploit
this to crash the system or gain elevated privil
Red Hat
kernel: megaraid_sas permissions in sysfs
vendor_redhat·2009-09-28·CVSS 7.1
CVE-2009-3939 [HIGH] kernel: megaraid_sas permissions in sysfs
kernel: megaraid_sas permissions in sysfs
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
Statement: This issue did not affect the version of the Linux kernel as shipped with Red Hat Enterprise Linux 3, as it does not implement the sysfs file system ("/sys/"), through which poll_mode_io file is exposed by the megaraid_sas driver.
GHSA
GHSA-3v99-jwxg-37h6: The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2
ghsa_unreviewed·2022-05-02
CVE-2009-3939 [MEDIUM] CWE-732 GHSA-3v99-jwxg-37h6: The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.htmlhttp://osvdb.org/60201http://secunia.com/advisories/37909http://secunia.com/advisories/38017http://secunia.com/advisories/38276http://secunia.com/advisories/38492http://secunia.com/advisories/38779http://support.avaya.com/css/P8/documents/100073666http://www.debian.org/security/2010/dsa-1996http://www.openwall.com/lists/oss-security/2009/11/13/1http://www.securityfocus.com/bid/37019http://www.ubuntu.com/usn/usn-864-1https://bugzilla.redhat.com/show_bug.cgi?id=526068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10310https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7540https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.htmlhttp://osvdb.org/60201http://secunia.com/advisories/37909http://secunia.com/advisories/38017http://secunia.com/advisories/38276http://secunia.com/advisories/38492http://secunia.com/advisories/38779http://support.avaya.com/css/P8/documents/100073666http://www.debian.org/security/2010/dsa-1996http://www.openwall.com/lists/oss-security/2009/11/13/1http://www.securityfocus.com/bid/37019http://www.ubuntu.com/usn/usn-864-1https://bugzilla.redhat.com/show_bug.cgi?id=526068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10310https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7540https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.html
2009-11-16
Published