CVE-2009-2584
Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain privileges via a crafted count argument, which triggers a stack-based buffer overflow.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://grsecurity.net/~spender/exploit_demo.cExploit, Third Party Advisory
- http://lkml.org/lkml/2009/7/20/348Exploit, Mailing List, Third Party Advisory
- http://lkml.org/lkml/2009/7/20/362Mailing List, Third Party Advisory
- http://secunia.com/advisories/37105Third Party Advisory
- http://www.securityfocus.com/bid/35753Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- http://xorl.wordpress.com/2009/07/21/linux-kernel-sgi-gru-driver-off-by-one-overwrite/Exploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51887Third Party Advisory, VDB Entry
- http://grsecurity.net/~spender/exploit_demo.cExploit, Third Party Advisory
- http://lkml.org/lkml/2009/7/20/348Exploit, Mailing List, Third Party Advisory
- http://lkml.org/lkml/2009/7/20/362Mailing List, Third Party Advisory
- http://secunia.com/advisories/37105Third Party Advisory
- http://www.securityfocus.com/bid/35753Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- http://xorl.wordpress.com/2009/07/21/linux-kernel-sgi-gru-driver-off-by-one-overwrite/Exploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51887Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.