peter bassill · operator
$ cve CVE-2009-3547 JSON

CVE-2009-3547 EXPLOIT

7.0
HIGH · CVSS 3.1 · EPSS 4.9% (pctl 92)

Patch early

A public exploit exists.

Description

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.

Scoring

CVSS7.0 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS4.89% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-362
On CISA KEVno
Public exploityes
Published2009-11-04
Last modified2026-06-16

Affected (14)

VendorProduct
canonicalubuntu linux
fedoraprojectfedora
linuxlinux kernel
novelllinux desktop
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux workstation
redhatmrg realtime
susesuse linux enterprise desktop
susesuse linux enterprise server
vmwareesx
vmwarevma

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD