Unrated severityNVD Advisory· Published Oct 22, 2009· Updated Apr 23, 2026
CVE-2009-2911
CVE-2009-2911
Description
SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.openwall.com/lists/oss-security/2009/10/21/1nvdPatch
- sources.redhat.com/bugzilla/show_bug.cginvdExploit
- www.vupen.com/english/advisories/2009/2989nvdVendor Advisory
- gcc.gnu.org/bugzilla/show_bug.cginvd
- secunia.com/advisories/37167nvd
- www.securityfocus.com/bid/36778nvd
- bugzilla.redhat.com/show_bug.cginvd
- www.redhat.com/archives/fedora-package-announce/2009-October/msg00627.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-October/msg00793.htmlnvd
News mentions
0No linked articles in our index yet.