← All CVEs

CVE-2009-1185

high · 7.2

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

7.2
CVSS
81.5%
EPSS (exploit prob.)
100th
EPSS percentile
2009-04-17
Published

AV:L/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-346

Affected products

VendorProductAffected versions
udev_projectudev< 141
suselinux_enterprise_debuginfo10
suselinux_enterprise_debuginfo11
opensuseopensuse10.3
opensuseopensuse11.0
opensuseopensuse11.1
suselinux_enterprise_desktop10
suselinux_enterprise_desktop11
suselinux_enterprise_server10
suselinux_enterprise_server11
debiandebian_linux4.0
debiandebian_linux5.0
canonicalubuntu_linux6.06
canonicalubuntu_linux7.10
canonicalubuntu_linux8.04
canonicalubuntu_linux8.10
fedoraprojectfedora9
fedoraprojectfedora10
juniperctpview< 7.1
juniperctpview7.1
juniperctpview7.1
juniperctpview7.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1185