CVE-2009-0748
Summary
| CVE | CVE-2009-0748 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-27 17:30:09 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The ext4_fill_super function in fs/ext4/super.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate the superblock configuration, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) by attempting to mount a crafted ext4 filesystem. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:L/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.27 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc7 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc8 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27 | rc9 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.27.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | rc7 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Red Hat update for kernel - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for linux-2.6 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1749-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | kernel.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| VMware ESX and vMA Update for Multiple Packages - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| USN-751-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| osvdb.org/52203 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| VMSA-2009-0016.1 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| 12371 – oops in ext4_get_group_desc | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.kernel.org | Exploit |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | kernel.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-09-02 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and Red Hat Enterprise MRG. This issue was addressed in Red Hat Enterprise Linux 5 by https://rhn.redhat.com/errata/RHSA-2009-1243.html |
There are currently no legacy QID mappings associated with this CVE.