High severity7.8NVD Advisory· Published Aug 14, 2009· Updated Apr 23, 2026
CVE-2009-2768
CVE-2009-2768
Description
The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by executing a shared flat binary, which triggers an access of an "uninitialized cred pointer."
Affected products
6cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <2.6.31
- cpe:2.3:o:linux:linux_kernel:2.6.31:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.31:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.31:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.31:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.31:rc5:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- lkml.org/lkml/2009/6/22/91nvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2009/08/13/1nvdMailing ListPatchThird Party Advisory
- www.securityfocus.com/bid/36037nvdBroken LinkThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/52909nvdThird Party AdvisoryVDB Entry
- secunia.com/advisories/36278nvdBroken Link
- thread.gmane.org/gmane.linux.hardware.blackfin.kernel.devel/1905nvdBroken Link
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5nvdBroken Link
- www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6nvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
News mentions
0No linked articles in our index yet.