CVE-2009-1895 describes a vulnerability in the Linux kernel's personality subsystem (before version 2.6.31-rc3) where the PER_CLEAR_ON_SETID setting fails to clear critical memory layout flags during setuid/setgid program execution. This flaw primarily impacts various distributions of Linux, including Canonical and Debian. The vulnerability carries a CVSS score of 7.2 (High), indicating a local attack vector with low complexity, allowing an unauthenticated attacker to achieve complete confidentiality, integrity, and availability impacts. Specifically, it facilitates NULL pointer dereference attacks, bypasses mmap_min_addr protection, and defeats Address Space Layout Randomization (ASLR). There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.31CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.31CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.31:rc1:*:*:*:*:*:* | ||
2.6.31CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.31:rc2:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.