CVE-2009-1961
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
- Affected products
- Cluster-Network-Kmp-Default, Cluster-Network-Kmp-Pae, Cluster-Network-Kmp-Ppc64, Cluster-Network-Kmp-Xen, Ext4Dev-Kmp-Default, Ext4Dev-Kmp-Pae, Ext4Dev-Kmp-Ppc64, Ext4Dev-Kmp-Vmi
- Linux Linux Kernel
- ≤ 2.6.19, 2.6.27.24, 2.6.29.4, 2.6.30
- CVSS 3.1
- 4.7 MEDIUM
- EPSS
- 0.6% (46th percentile)
- Weakness
- CWE-667
- NVD status
- Modified
- Published
- 2009-06-06
CVE-2009-1961 at NVD
1 known exploit for CVE-2009-1961
Proof-of-concept code and exploit modules indexed by Sploitus