{"api_version":"1","generated_at":"2026-07-23T09:50:02+00:00","cve":"CVE-2009-1388","urls":{"html":"https://cve.report/CVE-2009-1388","api":"https://cve.report/api/cve/CVE-2009-1388.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1388","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1388"},"summary":{"title":"CVE-2009-1388","description":"The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.","state":"PUBLISHED","assigner":"redhat","published_at":"2009-07-05 16:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-667","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8625","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8625","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/3316","name":"http://www.vupen.com/english/advisories/2009/3316","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/attachment.cgi?id=346615","name":"https://bugzilla.redhat.com/attachment.cgi?id=346615","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8680","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2009-1193.html","name":"http://www.redhat.com/support/errata/RHSA-2009-1193.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/55679","name":"http://osvdb.org/55679","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/37471","name":"http://secunia.com/advisories/37471","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"VMware ESX and vMA Update for Multiple Packages - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=oss-security&m=124654277229434&w=2","name":"http://marc.info/?l=oss-security&m=124654277229434&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch"],"title":"'[oss-security] CVE-2009-1388 kernel: do_coredump() vs ptrace_start() deadlock' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded","name":"http://www.securityfocus.com/archive/1/507985/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=504263","name":"https://bugzilla.redhat.com/show_bug.cgi?id=504263","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"],"title":"Bug 504263 – CVE-2009-1388 kernel: do_coredump() vs ptrace_start() deadlock","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","name":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"VMSA-2009-0016.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36131","name":"http://secunia.com/advisories/36131","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Red Hat update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/attachment.cgi?id=346742","name":"https://bugzilla.redhat.com/attachment.cgi?id=346742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35559","name":"http://www.securityfocus.com/bid/35559","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Linux Kernel 'ptrace_start()' And 'do_coredump()' Deadlock Local Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1388","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1388","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1388","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-1388","organization":"Red Hat","lastmodified":"2009-08-05","contributor":"Tomas Hoger","statementText":"This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise 5 via: https://rhn.redhat.com/errata/RHSA-2009-1193.html","cve_year":"2009","cve_id":"1388","crc32":"f9096ebe"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:13:25.447Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"36131","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36131"},{"name":"37471","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37471"},{"name":"oval:org.mitre.oval:def:8680","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8680"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"RHSA-2009:1193","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1193.html"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/attachment.cgi?id=346615"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=504263"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/attachment.cgi?id=346742"},{"name":"55679","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/55679"},{"name":"oval:org.mitre.oval:def:8625","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8625"},{"name":"35559","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35559"},{"name":"[oss-security] 20090702 CVE-2009-1388 kernel: do_coredump() vs ptrace_start() deadlock","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=oss-security&m=124654277229434&w=2"},{"name":"ADV-2009-3316","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3316"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-07-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"36131","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36131"},{"name":"37471","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37471"},{"name":"oval:org.mitre.oval:def:8680","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8680"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"RHSA-2009:1193","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1193.html"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/attachment.cgi?id=346615"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=504263"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/attachment.cgi?id=346742"},{"name":"55679","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/55679"},{"name":"oval:org.mitre.oval:def:8625","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8625"},{"name":"35559","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35559"},{"name":"[oss-security] 20090702 CVE-2009-1388 kernel: do_coredump() vs ptrace_start() deadlock","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=oss-security&m=124654277229434&w=2"},{"name":"ADV-2009-3316","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3316"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2009-1388","datePublished":"2009-07-05T16:00:00.000Z","dateReserved":"2009-04-23T00:00:00.000Z","dateUpdated":"2024-08-07T05:13:25.447Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-07-05 16:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-667","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*","matchCriteriaId":"C06F0037-DE20-4B4A-977F-BFCFAB026517"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1388","Ordinal":"1","Title":"CVE-2009-1388","CVE":"CVE-2009-1388","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1388","Ordinal":"1","NoteData":"The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.","Type":"Description","Title":"CVE-2009-1388"},{"CveYear":"2009","CveId":"1388","Ordinal":"2","NoteData":"2009-07-05","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1388","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}