6.9
CVSSv2

CVE-2009-1527

Published: 05/05/2009 Updated: 07/11/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel prior to 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to locking an incorrect cred_exec_mutex object.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.30

linux linux kernel

Exploits

/* ptrace_attach privilege escalation exploit by s0m3b0dy [*] tested on Gentoo 2629rc1 grataz: Tazo, rassta, nukedclx, maciek, D0hannuk, mivus, wacky, nejmo, filo email: s0m3b0dy1 (at) gmailcom */ #include <grph> #include <stdioh> #include <fcntlh> #include <errnoh> #include <pathsh> #include <string ...