CVE-2009-2857
CVE-2009-2857 is a medium-severity vulnerability in Oracle Opensolaris with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-667.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- CVSS v2: 4.9
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-667
- Affected product: Oracle Opensolaris
- Published:
- Last modified:
Description
The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.
Frequently asked questions
- What is CVE-2009-2857?
- The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.
- How severe is CVE-2009-2857?
- CVE-2009-2857 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2009-2857 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2009-2857?
- CVE-2009-2857 primarily affects Oracle Opensolaris. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2009-2857?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2009-2857 published?
- CVE-2009-2857 was published on 2009-08-19 and last updated on 2026-06-16.
References
- http://secunia.com/advisories/36319
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-127721-02-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-257848-1
- http://www.vupen.com/english/advisories/2009/2291
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6152
Affected products (4)
- cpe:2.3:o:oracle:opensolaris:*:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:8:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:9:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
More vulnerabilities in Oracle Opensolaris
- CVE-2010-3578 — Critical (CVSS 9.0): Unspecified vulnerability in Oracle OpenSolaris allows remote attackers to affect confidentiality, integrity, and…
- CVE-2010-0083 — High (CVSS 7.6): Unspecified vulnerability in Oracle OpenSolaris 8, 9, and 10 allows remote attackers to affect confidentiality,…
- CVE-2010-0882 — High (CVSS 7.2): Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_134 allows local…
- CVE-2010-3577 — Medium (CVSS 6.4): Unspecified vulnerability in Oracle OpenSolaris allows remote attackers to affect confidentiality and integrity,…
- CVE-2010-3503 — Medium (CVSS 6.3): Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and…
- CVE-2010-0916 — Medium (CVSS 6.2): Unspecified vulnerability in Oracle OpenSolaris 10 allows local users to affect confidentiality, integrity, and…
All CVEs affecting Oracle Opensolaris →
Other CWE-667 (Improper Locking) vulnerabilities
- CVE-2026-53049 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function…
- CVE-2025-22077 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: Revert "smb: client: fix TCP timers deadlock after…
- CVE-2024-58087 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and…
- CVE-2021-47587 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net: systemport: Add global locking for descriptor…
- CVE-2020-12658 — Critical (CVSS 9.8): gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in…
- CVE-2019-5886 — Critical (CVSS 9.8): An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation…