CVE-2009-1897
CVE-2009-1897
The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer dereference and an mmap of /dev/net/tun, a different vulnerability than CVE-2009-1894.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/33088unverifiedexploitdbwww.exploit-db.com/exploits/9191unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0241.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2009-07/0246.htmlhttp://article.gmane.org/gmane.linux.network/124939http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c8a9c63d5fd738c261bd0ceece04d9c8357ca13http://grsecurity.net/~spender/cheddar_bay.tgzhttp://isc.sans.org/diary.html?storyid=6820http://lkml.org/lkml/2009/7/6/19https://bugzilla.redhat.com/show_bug.cgi?id=512284http://secunia.com/advisories/35839https://exchange.xforce.ibmcloud.com/vulnerabilities/51803https://www.redhat.com/en/blog/security-flaws-caused-compiler-optimizationshttp://www.openwall.com/lists/oss-security/2009/07/17/1