AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-2908

MEDIUM · CVSS 4.9 EPSS 1.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-10-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-2908
Severity
MEDIUM
CVSS
4.9
EPSS
1.24%
Linux

Original NVD Description

The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount.