---
title: "CVE-2009-4895\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-4895?format=md
keywords: index, follow
---

# CVE-2009-4895

Publication date 8 September 2010

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**4.7 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2009-4895?format=md#impact-score)

Toggle side navigation

## Description

Race condition in the tty\_fasync function in drivers/char/tty\_io.c in the
Linux kernel before 2.6.32.6 allows local users to cause a denial of
service (NULL pointer dereference and system crash) or possibly have
unspecified other impact via unknown vectors, related to the put\_tty\_queue
and \_\_f\_setown functions. NOTE: the vulnerability was addressed in a
different way in 2.6.32.9.

### From the Ubuntu Security Team

Al Viro discovered a race condition in the TTY driver. A local attacker
could exploit this to crash the system, leading to a denial of service.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2009-4895?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux | 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Fixed 2.6.31-22.67 |
| 9.04 jaunty | Fixed 2.6.28-19.66 |
| 8.04 LTS hardy | Not affected |
| 6.06 LTS dapper | Not in release |
| linux-ec2 | 10.10 maverick | Ignored end of life |
| 10.04 LTS lucid | Fixed 2.6.32-309.18 |
| 9.10 karmic | Fixed 2.6.31-307.21 |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| linux-fsl-imx51 | 10.10 maverick | Not in release |
| 10.04 LTS lucid | Fixed 2.6.31-608.22 |
| 9.10 karmic | Fixed 2.6.31-112.30 |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| linux-lts-backport-maverick | 10.10 maverick | Not in release |
| 10.04 LTS lucid | Fixed 2.6.35-25.44~lucid1 |
| 9.10 karmic | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| linux-source-2.6.15 | 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 9.10 karmic | Not in release |
| 9.04 jaunty | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2009-4895?format=md#patch-details)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

first patch (703625118069f9f8) was reverted and the second
patch was used in 2.6.32.9, which fixes the issue "properly".

---

### [smb](https://launchpad.net/~smb)

IMO the races in tty became visible when the BLK was pushed down into
the line disciplines and switch to unlocked ioctl in 2.6.26
(04f378b198da233ca0aca341b113dc6579d46123), so Hardy and Dapper are not
affected.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| linux | * Upstream:   <http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=703625118069f9f8960d356676662d3db5a9d116> * Upstream:   <http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=80e1e823989ec44d8e35bdfddadbddcffec90424> * Jaunty:   <http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2009-4895/patches/jaunty/linux/0001-Fix-race-in-tty_fasync-properly.txt> * Karmic:   <http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2009-4895/patches/karmic/linux/0001-Fix-race-in-tty_fasync-properly.txt> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

4.7 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 4.7 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4895)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-4895)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-4895)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-4895)

### Related Ubuntu Security Notices (USN)

+ [USN-1074-1](https://usn.ubuntu.com/USN-1074-1)
+ Linux kernel vulnerabilities
+ 25 February 2011

+ [USN-1083-1](https://usn.ubuntu.com/USN-1083-1)
+ Linux kernel vulnerabilities
+ 3 March 2011

+ [USN-1000-1](https://usn.ubuntu.com/USN-1000-1)
+ Linux kernel vulnerabilities
+ 19 October 2010

+ [USN-1074-2](https://usn.ubuntu.com/USN-1074-2)
+ Linux kernel vulnerabilities
+ 28 February 2011

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-4895>
