Candidate: CVE-2009-1897 PublicDate: 2009-07-20 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1897 Description: The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer dereference and an mmap of /dev/net/tun, a different vulnerability than CVE-2009-1894. Ubuntu-Description: Notes: Bugs: Priority: high Discovered-by: Assigned-to: CVSS: Patches_linux-source-2.6.15: upstream_linux-source-2.6.15: needs-triage dapper_linux-source-2.6.15: not-affected (2.6.15.55) hardy_linux-source-2.6.15: DNE intrepid_linux-source-2.6.15: DNE jaunty_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux: upstream_linux: needs-triage dapper_linux: DNE hardy_linux: not-affected (2.6.24.24.26) intrepid_linux: not-affected (2.6.27.14.18) jaunty_linux: not-affected (2.6.28.13.17) devel_linux: not-affected (2.6.31.3.14)