CVE
- Id
- 41576
- CVE No.
- CVE-2009-4141
- Status
- Candidate
- Description
- Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.
- Phase
- Assigned (20091201)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
456701 | 41576 | CVE-2009-4141 | FULLDISC:20100114 Locked fasync file descriptors can be referenced after free in >= 2.6.28 | View |
456702 | 41576 | CVE-2009-4141 | URL:http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0252.html | View |
456703 | 41576 | CVE-2009-4141 | MISC:http://lock.cmpxchg8b.com/5ebe2294ecd0e0f08eab7690d2a6ee69/create_elf_tables.c | View |
456704 | 41576 | CVE-2009-4141 | MISC:http://twitter.com/taviso/statuses/7744108017 | View |
456705 | 41576 | CVE-2009-4141 | CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=53281b6d34d44308372d16acb7fb5327609f68b6 | View |
456706 | 41576 | CVE-2009-4141 | CONFIRM:http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.33-rc4-git1.bz2 | View |
456707 | 41576 | CVE-2009-4141 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=547906 | View |
456708 | 41576 | CVE-2009-4141 | CONFIRM:http://support.avaya.com/css/P8/documents/100073666 | View |
456709 | 41576 | CVE-2009-4141 | REDHAT:RHSA-2010:0046 | View |
456710 | 41576 | CVE-2009-4141 | URL:https://rhn.redhat.com/errata/RHSA-2010-0046.html | View |
456711 | 41576 | CVE-2009-4141 | REDHAT:RHSA-2010:0095 | View |
456712 | 41576 | CVE-2009-4141 | URL:https://rhn.redhat.com/errata/RHSA-2010-0095.html | View |
456713 | 41576 | CVE-2009-4141 | REDHAT:RHSA-2010:0161 | View |
456714 | 41576 | CVE-2009-4141 | URL:http://www.redhat.com/support/errata/RHSA-2010-0161.html | View |
456715 | 41576 | CVE-2009-4141 | SUSE:SUSE-SA:2010:010 | View |
456716 | 41576 | CVE-2009-4141 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html | View |
456717 | 41576 | CVE-2009-4141 | BID:37806 | View |
456718 | 41576 | CVE-2009-4141 | URL:http://www.securityfocus.com/bid/37806 | View |
456719 | 41576 | CVE-2009-4141 | OVAL:oval:org.mitre.oval:def:7054 | View |
456720 | 41576 | CVE-2009-4141 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7054 | View |
456721 | 41576 | CVE-2009-4141 | OVAL:oval:org.mitre.oval:def:9201 | View |
456722 | 41576 | CVE-2009-4141 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9201 | View |
456723 | 41576 | CVE-2009-4141 | SECUNIA:38199 | View |
456724 | 41576 | CVE-2009-4141 | URL:http://secunia.com/advisories/38199 | View |
456725 | 41576 | CVE-2009-4141 | SECUNIA:39033 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
41503 | JVNDB-2009-002510 | NetworkManager の nm-connection-editor における重要な情報を取得される脆弱性 | NetworkManager の nm-connection-editor には、接続エディタの GUI の動作に応じて D-Bus 経由で接続オブジェクトをエクスポートするため、重要な情報を取得される脆弱性が存在します。 | CVE-2009-4145 | 41576 | 2.1 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002510.html | View |