CVE-2009-0835
Summary
| CVE | CVE-2009-0835 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-06 11:30:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.25 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.1 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.10 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.11 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.12 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.2 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.3 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.4 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.5 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.6 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.7 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.8 | All | x86_64 | All |
| Operating System | Linux | Linux Kernel | 2.6.25.9 | All | x86_64 | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Linux Kernel 'seccomp' System Call Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CESA-2009-004 - rev 1 | af854a3a-2127-422b-91ae-364da2661108 | scary.beasts.org | |
| '[PATCH 0/2] x86-64: 32/64 syscall arch holes' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Bug 487255 – CVE-2009-0835 kernel: x86-64: seccomp: 32/64 syscall hole | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Exploit |
| SUSE update for kernel - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support / Security / Advisories / / MDVSA-2009:118 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| '[oss-security] CVE request: kernel: x86-64: seccomp: 32/64 syscall hole' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA35390 - SUSE update for kernel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SUSE update for kernel - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for kernel-rt - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CESA-2009-001 - rev 1 | af854a3a-2127-422b-91ae-364da2661108 | scary.beasts.org | Exploit |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for linux-2.6 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Linux Kernel 32bit/64bit System Call Security Bypass Weaknesses - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| LKML: Roland McGrath: Re: [PATCH 2/2] x86-64: seccomp: fix 32/64 syscall hole | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security: Linux kernel minor "seccomp" vulnerability | af854a3a-2127-422b-91ae-364da2661108 | scarybeastsecurity.blogspot.com | |
| Debian -- Security Information -- DSA-1800-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| USN-751-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| '[PATCH 2/2] x86-64: seccomp: fix 32/64 syscall hole' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Exploit |
| SUSE update for kernel - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-05-19 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5. It was addressed in Red Hat Enterprise MRG via: https://rhn.redhat.com/errata/RHSA-2009-0451.html . |
There are currently no legacy QID mappings associated with this CVE.