CVE-2009-3547 EXPLOIT
7.0
HIGH · CVSS 3.1 · EPSS 4.9% (pctl 92)
Patch early
A public exploit exists.
Description
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.
Scoring
| CVSS | 7.0 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.89% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-362 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-11-04 |
| Last modified | 2026-06-16 |
Affected (14)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| fedoraproject | fedora |
| linux | linux kernel |
| novell | linux desktop |
| opensuse | opensuse |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
| redhat | mrg realtime |
| suse | suse linux enterprise desktop |
| suse | suse linux enterprise server |
| vmware | esx |
| vmware | vma |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel 2.6.10 < 2.6.31.5 - 'pipe.c' Local Privilege Escalation | 2013-12-16 |
| exploit-db | Linux Kernel 2.6.32 - 'pipe.c' Local Privilege Escalation (4) | 2009-11-12 |
| exploit-db | Linux Kernel 2.4.1 < 2.4.37 / 2.6.1 < 2.6.32-rc5 - 'pipe.c' Local Privilege Escalation (3) | 2009-11-05 |
| exploit-db | Linux Kernel 2.6.0 < 2.6.31 - 'pipe.c' Local Privilege Escalation (1) | 2009-11-03 |
| exploit-db | Linux Kernel 2.6.x - 'pipe.c' Local Privilege Escalation (2) | 2009-11-03 |
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ad3960243e55320d74195fb85c975e0a8cc4466c
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html
- http://lkml.org/lkml/2009/10/14/184
- http://lkml.org/lkml/2009/10/21/42
- http://marc.info/?l=oss-security&m=125724568017045&w=2
- http://secunia.com/advisories/37351
- http://secunia.com/advisories/38017
- http://secunia.com/advisories/38794
- http://secunia.com/advisories/38834
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc6
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:329
- http://www.redhat.com/support/errata/RHSA-2009-1672.html
- http://www.securityfocus.com/archive/1/512019/100/0/threaded
- http://www.securityfocus.com/bid/36901
- http://www.ubuntu.com/usn/usn-864-1
- http://www.vupen.com/english/advisories/2010/0528
→ the Explorer · watch your stack · NVD