VulnerabilityModified
CVE-2009-1185
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
HIGH 7.2EPSS 81.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 81.5%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 81.53% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- udev project/udev · suse/linux enterprise debuginfo · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · debian/debian linux · canonical/ubuntu linux · fedoraproject/fedora · juniper/ctpview
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=e2b362d9f23d4c63018709ab5f81a02f72b91e75
- http://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=e86a923d508c2aed371cdd958ce82489cf2ab615
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00012.htmlMailing List, Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000060.htmlThird Party Advisory
- http://secunia.com/advisories/34731Not Applicable
- http://secunia.com/advisories/34750Not Applicable
- http://secunia.com/advisories/34753Not Applicable
- http://secunia.com/advisories/34771Not Applicable
- http://secunia.com/advisories/34776Not Applicable
- http://secunia.com/advisories/34785Not Applicable
- http://secunia.com/advisories/34787Not Applicable
- http://secunia.com/advisories/34801Not Applicable
- http://secunia.com/advisories/35766Not Applicable
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.446399Mailing List, Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0063Broken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063Broken Link
- http://www.debian.org/security/2009/dsa-1772Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200904-18.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:103Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:104Broken Link
- http://www.redhat.com/support/errata/RHSA-2009-0427.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/502752/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/504849/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/34536Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022067Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-758-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2009-0009.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.