CVE-2009-3547 describes multiple race conditions in the Linux kernel's pipe.c, affecting various Linux distributions including Canonical, Fedora, Red Hat, and SUSE. This vulnerability allows local users to cause a denial of service (system crash) or escalate privileges by manipulating anonymous pipes. Rated High (CVSS 7.0), it requires low privileges but high attack complexity, with potential for complete confidentiality, integrity, and availability compromise. While not on the CISA KEV catalog, multiple exploit proofs-of-concept are publicly available on ExploitDB, indicating its exploitability, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.31.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.32CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32:-:*:*:*:*:*:* | ||
2.6.32CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32:rc1:*:*:*:*:*:* | ||
2.6.32CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32:rc2:*:*:*:*:*:* | ||
2.6.32CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.32:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.