First published: Wed Jan 27 2010(Updated: )
Description of problem: Changes to tty to use struct pid happened here: ab521dc0f8e117fd808d3e425216864d60390500 mrg-1/rhel-6 are missing: 1) redo locking of tty->pgrp 47f86834bbd4193139d61d659bebf9ab9d691e37 2) tty: fix race in tty_fasync 703625118069f9f8960d356676662d3db5a9d116 3) fnctl: f_modown should call write_lock_irqsave/restore b04da8bfdfbbd79544cab2fadfdc12e87eb01600
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux-2.6 | ||
Linux kernel | <2.6.32.6 | |
Debian | =5.0 | |
Ubuntu Linux | =6.06 | |
Ubuntu Linux | =8.04 | |
Ubuntu Linux | =9.04 | |
Ubuntu Linux | =9.10 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =10.10 | |
Linux Kernel | <2.6.32.6 | |
Ubuntu | =6.06 | |
Ubuntu | =8.04 | |
Ubuntu | =9.04 | |
Ubuntu | =9.10 | |
Ubuntu | =10.04 | |
Ubuntu | =10.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4895 has a medium severity due to potential race conditions affecting tty devices.
To fix CVE-2009-4895, apply the relevant patches from your Linux distribution that address the tty locking issues.
CVE-2009-4895 affects various versions of the Linux kernel including those prior to 2.6.32.6 and specific Debian and Ubuntu releases.
CVE-2009-4895 can lead to privilege escalation or denial of service due to improper handling of concurrent tty operations.
Systems running affected versions of the Linux kernel, Debian Linux 5.0, or specific Ubuntu releases like 6.06 to 10.10 are vulnerable to CVE-2009-4895.