{"api_version":"1","generated_at":"2026-07-23T09:58:36+00:00","cve":"CVE-2009-2908","urls":{"html":"https://cve.report/CVE-2009-2908","api":"https://cve.report/api/cve/CVE-2009-2908.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2908","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2908"},"summary":{"title":"CVE-2009-2908","description":"The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a \"negative dentry\" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount.","state":"PUBLISHED","assigner":"redhat","published_at":"2009-10-13 10:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10216","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10216","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37075","name":"http://secunia.com/advisories/37075","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38794","name":"http://secunia.com/advisories/38794","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMware vMA Update for Multiple Packages - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/10/06/1","name":"http://www.openwall.com/lists/oss-security/2009/10/06/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Kernel ecryptfs CVE id (CVE-2009-2908)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36639","name":"http://www.securityfocus.com/bid/36639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Linux Kernel eCryptfs Lower Dentry Null Pointer Dereference Local Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/37105","name":"http://secunia.com/advisories/37105","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ubuntu update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git%3Ba=commit%3Bh=afc2b6932f48f200736d3e36ad66fee0ec733136","name":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git%3Ba=commit%3Bh=afc2b6932f48f200736d3e36ad66fee0ec733136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2010/0528","name":"http://www.vupen.com/english/advisories/2010/0528","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6992","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6992","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-852-1","name":"http://www.ubuntu.com/usn/USN-852-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-852-1: Linux kernel vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.launchpad.net/ecryptfs/+bug/387073","name":"https://bugs.launchpad.net/ecryptfs/+bug/387073","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug #387073 “BUG: unable to handle kernel NULL pointer dereferen...” : Bugs : eCryptfs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00483.html","name":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00483.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 10 Update: kernel-2.6.27.37-170.2.104.fc10","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53693","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53693","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.vmware.com/pipermail/security-announce/2010/000082.html","name":"http://lists.vmware.com/pipermail/security-announce/2010/000082.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Security-announce] VMSA-2010-0004 ESX Service Console and vMA\tthird party updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=527534","name":"https://bugzilla.redhat.com/show_bug.cgi?id=527534","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 527534 – CVE-2009-2908 kernel ecryptfs NULL pointer dereference","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38834","name":"http://secunia.com/advisories/38834","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMware ESX Server 4 Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2009-1548.html","name":"https://rhn.redhat.com/errata/RHSA-2009-1548.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git;a=commit;h=afc2b6932f48f200736d3e36ad66fee0ec733136","name":"CONFIRM:http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git;a=commit;h=afc2b6932f48f200736d3e36ad66fee0ec733136","refsource":"MITRE","tags":[],"title":"","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://access.redhat.com/errata/RHSA-2009:1548","name":"MISC:https://access.redhat.com/errata/RHSA-2009:1548","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2009-2908","name":"MISC:https://access.redhat.com/security/cve/CVE-2009-2908","refsource":"MITRE","tags":[],"title":"access.redhat.com | CVE-2009-2908","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2908","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2908","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2908","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-2908","organization":"Red Hat","lastmodified":"2009-11-04","contributor":"Tomas Hoger","statementText":"The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat Enterprise MRG do not include support for eCryptfs, and therefore are not affected by this issue. It was addressed in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2009-1548.html","cve_year":"2009","cve_id":"2908","crc32":"475478b1"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:07:37.270Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"USN-852-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-852-1"},{"name":"38794","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38794"},{"name":"[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.vmware.com/pipermail/security-announce/2010/000082.html"},{"name":"kernel-ecryptfs-dos(53693)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53693"},{"name":"oval:org.mitre.oval:def:10216","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10216"},{"name":"37075","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37075"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git%3Ba=commit%3Bh=afc2b6932f48f200736d3e36ad66fee0ec733136"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=527534"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugs.launchpad.net/ecryptfs/+bug/387073"},{"name":"RHSA-2009:1548","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2009-1548.html"},{"name":"38834","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38834"},{"name":"FEDORA-2009-10525","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00483.html"},{"name":"oval:org.mitre.oval:def:6992","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6992"},{"name":"[oss-security] 20091006 Kernel ecryptfs CVE id (CVE-2009-2908)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/10/06/1"},{"name":"36639","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36639"},{"name":"37105","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37105"},{"name":"ADV-2010-0528","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0528"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-10-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a \"negative dentry\" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"USN-852-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-852-1"},{"name":"38794","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38794"},{"name":"[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.vmware.com/pipermail/security-announce/2010/000082.html"},{"name":"kernel-ecryptfs-dos(53693)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53693"},{"name":"oval:org.mitre.oval:def:10216","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10216"},{"name":"37075","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37075"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git%3Ba=commit%3Bh=afc2b6932f48f200736d3e36ad66fee0ec733136"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=527534"},{"tags":["x_refsource_MISC"],"url":"https://bugs.launchpad.net/ecryptfs/+bug/387073"},{"name":"RHSA-2009:1548","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://rhn.redhat.com/errata/RHSA-2009-1548.html"},{"name":"38834","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38834"},{"name":"FEDORA-2009-10525","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00483.html"},{"name":"oval:org.mitre.oval:def:6992","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6992"},{"name":"[oss-security] 20091006 Kernel ecryptfs CVE id (CVE-2009-2908)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/10/06/1"},{"name":"36639","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36639"},{"name":"37105","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37105"},{"name":"ADV-2010-0528","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0528"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2009-2908","datePublished":"2009-10-13T10:00:00.000Z","dateReserved":"2009-08-20T00:00:00.000Z","dateUpdated":"2024-08-07T06:07:37.270Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-10-13 10:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.31:*:*:*:*:*:*:*","matchCriteriaId":"C4033E0B-A3A1-4CC5-956A-AAA0FB905DDA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2908","Ordinal":"1","Title":"CVE-2009-2908","CVE":"CVE-2009-2908","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2908","Ordinal":"1","NoteData":"The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a \"negative dentry\" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount.","Type":"Description","Title":"CVE-2009-2908"},{"CveYear":"2009","CveId":"2908","Ordinal":"2","NoteData":"2009-10-13","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"2908","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}