CVE-2009-0859

Publication date 9 March 2009

Last updated 24 July 2024


Ubuntu priority

The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_INFO shmctl call, as demonstrated by running the ipcs program.

From the Ubuntu Security Team

The shared memory subsystem did not correctly handle certain shmctl calls when CONFIG_SHMEM was disabled. Ubuntu kernels were not vulnerable, since CONFIG_SHMEM is enabled by default.

Status

Package Ubuntu Release Status

References

Related Ubuntu Security Notices (USN)

    • USN-752-1
    • Linux kernel vulnerabilities
    • 7 April 2009
    • USN-751-1
    • Linux kernel vulnerabilities
    • 6 April 2009

Other references