CVE-2009-2406 describes a stack-based buffer overflow in the eCryptfs subsystem of the Linux kernel, affecting versions prior to 2.6.30.4. This vulnerability, located in the parse_tag_11_packet function, allows local users to trigger a denial of service or potentially gain privileges through a crafted eCryptfs file. With a CVSS score of 6.9, it is considered high severity due to its potential for complete confidentiality, integrity, and availability impact, though it requires medium attack complexity. There is no known exploit code available in common databases like Metasploit or ExploitDB, and it has received minimal community discussion or media coverage, indicating no active exploitation or widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.24.7CPE matchmatch criteria | cpe:2.3:a:linux:kernel:2.6.24.7:*:*:*:*:*:*:* | ||
2.6.25.15CPE matchmatch criteria | cpe:2.3:a:linux:kernel:2.6.25.15:*:*:*:*:*:*:* | ||
<= 2.6.30.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.2.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.2.6:*:*:*:*:*:*:* | ||
2.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.