CVE-2009-1185: High severity Udev Project Udev vulnerability
A privilege escalation flaw was found in the way udev used to check for the origin of messages sent from the NETLINK service. An attacker could use this flaw to escalate his privileges by sending the NETLINK message from userspace process, instead of from the kernel.
Acknowledgements:
Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for responsibly reporting this flaw.
Other sources
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1185?
CVE-2009-1185 is classified as a privilege escalation vulnerability.
How do I fix CVE-2009-1185?
To fix CVE-2009-1185, update the affected software to the latest patched version.
Which systems are affected by CVE-2009-1185?
CVE-2009-1185 affects various versions of udev, SUSE Linux, Debian, Ubuntu, and Fedora.
What is the impact of CVE-2009-1185?
The impact of CVE-2009-1185 allows attackers to escalate their privileges on the affected systems.
Is there a workaround for CVE-2009-1185?
There is no specific workaround for CVE-2009-1185; updating the software is the recommended solution.