CVE-2009-1337 EXPLOIT
4.4
MEDIUM · CVSS 2.0 · EPSS 1.3% (pctl 69)
Patch early
A public exploit exists.
Description
The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.
Scoring
| CVSS | 4.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 1.26% — more likely to be exploited than 69% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-04-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| linux | linux kernel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel < 2.6.29 - 'exit_notify()' Local Privilege Escalation | 2009-04-08 |
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=432870dab85a2f69dc417022646cb9a70acf7f94
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html
- http://marc.info/?l=linux-kernel&m=123560588713763&w=2
- http://patchwork.kernel.org/patch/16544/
- http://rhn.redhat.com/errata/RHSA-2009-0473.html
- http://secunia.com/advisories/34917
- http://secunia.com/advisories/34981
- http://secunia.com/advisories/35011
- http://secunia.com/advisories/35015
- http://secunia.com/advisories/35120
- http://secunia.com/advisories/35121
- http://secunia.com/advisories/35160
- http://secunia.com/advisories/35185
- http://secunia.com/advisories/35226
- http://secunia.com/advisories/35324
- http://secunia.com/advisories/35387
- http://secunia.com/advisories/35390
→ the Explorer · watch your stack · NVD