CVE-2009-0935 describes a denial-of-service vulnerability in the Linux kernel (versions 2.6.27-2.6.27.13, 2.6.28-2.6.28.2, and 2.6.29-rc3). A local attacker can trigger an OOPS by providing an invalid address to an inotify instance during a read operation, leading to a double unlock of the event list mutex and data structure synchronization issues. Rated as Medium severity (CVSS 5.5), this vulnerability requires local access and low privileges, with no user interaction needed. Its impact is limited to high availability, as it can cause a system crash. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.27, <= 2.6.27.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 2.6.28, <= 2.6.28.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.29CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.29:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.