CVE-2009-0746 is a denial-of-service vulnerability affecting the Linux kernel (versions 2.6.27 prior to 2.6.27.19 and 2.6.28 prior to 2.6.28.7). It allows local users to trigger a system crash (OOPS) by attempting to mount a specially crafted ext4 filesystem due to improper validation of the rec_len field in the make_indexed_dir function. With a CVSS score of 4.9, this vulnerability has a low attack complexity and requires local access, leading to a complete system availability impact. While not actively exploited in the wild, public exploit code exists on ExploitDB, though there is no evidence of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.27CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.27:*:*:*:*:*:*:* | ||
2.6.27.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.27.1:*:*:*:*:*:*:* | ||
2.6.27.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.27.2:*:*:*:*:*:*:* | ||
2.6.27.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.27.3:*:*:*:*:*:*:* | ||
2.6.27.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.27.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.