udev: Uncheck origin of NETLINK messages
Published Apr 17, 2009
7.2
HIGHCVSS 2.0
EPSS 80.42%
Description
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
Affected products
No data.
Configuration 1
- < 141
Configuration 2
- 10
- 11
- 10.3
- 11.0
- 11.1
- 10
- 11
- 10
- 11
Configuration 3
- 4.0
- 5.0
Configuration 4
- 6.06
- 7.10
- 8.04
- 8.10
Configuration 5
- 9
- 10
No data.
Red Hat Enterprise Linux 5
udev-0:095-14.20.el5_3
Fixed · RHSA-2009:0427
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | udev-0:095-14.20.el5_3 | Fixed | RHSA-2009:0427 |
No package ranges for this CVE.
Remediation
Red Hat statement
udev packages as shipped in Red Hat Enterprise Linux 4 are not affected by this flaw, as they do not use netlink sockets for communication. udev is not shipped in Red Hat Enterprise Linux 2.1 and 3.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 80.42% (0.80416) | 99.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 81.53% (0.81528) | 99.59th | v5 (v2026.06.15) |
| Oct 6, 2025 | 89.27% (0.89270) | 99.52th | v4 (v2025.03.14) |
| Apr 20, 2025 | 86.53% (0.86529) | 99.34th | v4 (v2025.03.14) |
| Mar 30, 2025 | 90.64% (0.90645) | 99.60th | v4 (v2025.03.14) |
| Mar 29, 2025 | 89.54% (0.89540) | 99.47th | v4 (v2025.03.14) |
| Mar 21, 2025 | 90.64% (0.90645) | 99.62th | v4 (v2025.03.14) |
| Mar 17, 2025 | 92.28% (0.92282) | 99.72th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00046) | 18.12th | v3 (v2023.03.01) |
| May 8, 2024 | 0.05% (0.00046) | 14.93th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 12.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.11% (0.02111) | 80.00th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.11% (0.02111) | 78.08th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.11% (0.02111) | 56.77th | v2 (v2022.01.01) |
References (42)
- http://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=e2b362d9f23d4c63018709ab5f81a02f72b91e75 x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=e86a923d508c2aed371cdd958ce82489cf2ab615 x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691 x_refsource_CONFIRMThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 x_refsource_CONFIRMThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00012.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000060.html mailing-listx_refsource_MLISTThird Party Advisory
- http://secunia.com/advisories/34731 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/34750 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/34753 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/34771 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/34776 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/34785 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/34787 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/34801 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/35766 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.446399 vendor-advisoryx_refsource_SLACKWAREMailing ListThird Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0063 x_refsource_CONFIRMBroken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063 x_refsource_MISCBroken Link
- http://www.debian.org/security/2009/dsa-1772 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200904-18.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:103 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:104 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.redhat.com/support/errata/RHSA-2009-0427.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/archive/1/502752/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/504849/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/34536 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1022067 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-758-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2009-0009.html x_refsource_CONFIRMThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1053 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1865 vdb-entryx_refsource_VUPENPermissions Required
- https://access.redhat.com/security/cve/CVE-2009-1185 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=495051 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://launchpad.net/bugs/cve/2009-1185 x_refsource_MISCIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1185
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10925 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5975 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-1185
- https://www.exploit-db.com/exploits/8572 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00462.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00463.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.