← back
CVE-2009-1897

CVE-2009-1897

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.5%
from disclosure to weapon0 days
Published on NVDJul 20
1st PoCJun 17
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer dereference and an mmap of /dev/net/tun, a different vulnerability than CVE-2009-1894.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.