CVE-2009-2691
Summary
| CVE | CVE-2009-2691 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-08-14 15:16:27 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.30 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30 | rc6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30 | rc7-git6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.30.2 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| LKML: Oleg Nesterov: [PATCH 0/1] mm_for_maps: simplify, use ptrace_may_access() | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-2005-1 linux-2.6.24 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 11 Update: kernel-2.6.29.6-217.2.16.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Linux Kernel "mm_for_maps()" Information Disclosure - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Fedora update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 504 Gateway Time-out | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| oss-security - CVE-2009-2691 kernel: /proc/$pid/maps visible during initial setuid ELF loading | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| 516171 – (CVE-2009-2691) CVE-2009-2691 kernel: /proc/$pid/maps visible during initial setuid ELF loading | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| '[PATCH 1/2] mm_for_maps: shift down_read(mmap_sem) to the caller' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Patch |
| LKML: Oleg Nesterov: [PATCH 1/1] mm_for_maps: simplify, use ptrace_may_access() | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | Patch |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| '[PATCH 2/2] mm_for_maps: take ->cred_guard_mutex to fix the race' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Patch |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-11-04 | Mark J Cox | The Red Hat Security Response Team has rated this issue as having moderate security impact. We currently have no plans to fix this flaw in Red Hat Enterprise Linux 3, 4, and 5 as it is not possible to trigger the information leak if the suid_dumpable tunable is set to zero (which is the default). It was addressed in Red Hat Enterprise MRG via: https://rhn.redhat.com/errata/RHSA-2009-1540.html |
There are currently no legacy QID mappings associated with this CVE.