CVE-2009-2767: Buffer Overflow
The initposixtimers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCKMONOTONICRAW clocknanosleep call that triggers a NULL pointer dereference.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2767?
CVE-2009-2767 has a severity level that can lead to denial of service and potential privilege escalation.
How do I fix CVE-2009-2767?
To fix CVE-2009-2767, upgrade to a Linux kernel version that is 2.6.31-rc6 or newer.
What is affected by CVE-2009-2767?
CVE-2009-2767 affects multiple versions of the Linux kernel prior to 2.6.31-rc6.
What does CVE-2009-2767 exploit?
CVE-2009-2767 exploits a vulnerability in the init_posix_timers function using the CLOCK_MONOTONIC_RAW clock_nanosleep call.
Who is affected by CVE-2009-2767?
Local users on systems running vulnerable versions of the Linux kernel can be affected by CVE-2009-2767.