CVE-2009-1385
Vulnerability Summary
Timeline
Description
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
CVSS Metrics
- v2.0•HIGH•Score: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 13.89%• Percentile: 94%
Techniques & Countermeasures
- CWE-189•Numeric Errors
Weaknesses in this category are related to improper calculation or conversion of numbers.
Affected Systems
- intel•e1000
≤ 7.4.35 | 5.2.22 | 5.2.30.1 | 5.2.52 | 5.3.19 | 5.4.11 | 5.5.4 | 5.6.10 | 5.6.10.1 | 5.7.6 | 6.0.54 | 6.0.60 | 6.1.16 | 6.2.15 | 6.3.9 | 7.0.33 | 7.0.41 | 7.1.9 | 7.2.7 | 7.2.9 | 7.3.15 | 7.3.20 | 7.4.27
- Unknown•Kernel
2.6.24.7 | 2.6.25.15
- linux•linux_kernel
≤ 2.6.28 | ≤ 2.6.30 | 2.2.27 | 2.4.36 | 2.4.36.1 | 2.4.36.2 | 2.4.36.3 | 2.4.36.4 | 2.4.36.5 | 2.4.36.6 | 2.6 | 2.6.18 | 2.6.18:rc1 | 2.6.18:rc2 | 2.6.18:rc3 | 2.6.18:rc4 | 2.6.18:rc5 | 2.6.18:rc6 | 2.6.18:rc7 | 2.6.19.4 | 2.6.19.5 | 2.6.19.6 | 2.6.19.7 | 2.6.20.16 | 2.6.20.17 | 2.6.20.18 | 2.6.20.19 | 2.6.20.20 | 2.6.20.21 | 2.6.21.5 | 2.6.21.6 | 2.6.21.7 | 2.6.22 | 2.6.22.1 | 2.6.22.2 | 2.6.22.8 | 2.6.22.9 | 2.6.22.10 | 2.6.22.11 | 2.6.22.12 | 2.6.22.13 | 2.6.22.14 | 2.6.22.15 | 2.6.22.17 | 2.6.22.18 | 2.6.22.19 | 2.6.22.20 | 2.6.22.21 | 2.6.22.22 | 2.6.22_rc1 | 2.6.22_rc7 | 2.6.23 | 2.6.23.8 | 2.6.23.9 | 2.6.23.10 | 2.6.23.11 | 2.6.23.12 | 2.6.23.13 | 2.6.23.15 | 2.6.23.16 | 2.6.23.17 | 2.6.23_rc1 | 2.6.24 | 2.6.24.1 | 2.6.24.2 | 2.6.24.3 | 2.6.24.4 | 2.6.24.5 | 2.6.24.6 | 2.6.24_rc1 | 2.6.24_rc4 | 2.6.24_rc5 | 2.6.25 | 2.6.25.1 | 2.6.25.2 | 2.6.25.3 | 2.6.25.4 | 2.6.25.5 | 2.6.25.6 | 2.6.25.7 | 2.6.25.8 | 2.6.25.9 | 2.6.25.10 | 2.6.25.11 | 2.6.25.12 | 2.6.25.13 | 2.6.25.14 | 2.6.25.16 | 2.6.25.17 | 2.6.26 | 2.6.26.1 | 2.6.26.2 | 2.6.26.3 | 2.6.26.4 | 2.6.26.5 | 2.6.27 | 2.6.29 | 2.6.29:git1 | 2.6.29:rc1 | 2.6.29:rc2 | 2.6.29:rc2_git7 | 2.6.29:rc8-kk | 2.6.29.3 | 2.6.29.rc1 | 2.6.29.rc2 | 2.6.29.rc2-git1 | 2.6.30:rc1 | 2.6.30:rc2 | 2.6.30:rc3
References (38)
- http://secunia.com/advisories/35265
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:135
- http://www.debian.org/security/2009/dsa-1865
- http://www.securityfocus.com/archive/1/512019/100/0/threaded
- http://wiki.rpath.com/Advisories:rPSA-2009-0111
- http://sourceforge.net/project/shownotes.php?release_id=504022&group_id=42302
- http://secunia.com/advisories/36131
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.html
- http://secunia.com/advisories/37471
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:148
- http://secunia.com/advisories/35656
- http://www.debian.org/security/2009/dsa-1844
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html
- http://www.redhat.com/support/errata/RHSA-2009-1193.html
- http://www.intel.com/support/network/sb/CS-030543.htm
- http://secunia.com/advisories/35566
- http://osvdb.org/54892
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11598
- http://www.redhat.com/support/errata/RHSA-2009-1157.html
- http://www.securityfocus.com/bid/35185
- http://www.securityfocus.com/archive/1/505254/100/0/threaded
- http://secunia.com/advisories/35623
- http://www.securityfocus.com/archive/1/507985/100/0/threaded
- http://secunia.com/advisories/36051
- http://secunia.com/advisories/36327
- http://www.ubuntu.com/usn/usn-793-1
- https://bugzilla.redhat.com/show_bug.cgi?id=502981
- http://www.openwall.com/lists/oss-security/2009/06/03/2
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11681
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8
- https://rhn.redhat.com/errata/RHSA-2009-1550.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8340
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.html
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ea30e11970a96cfe5e32c03a29332554573b4a10
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html
- http://www.vupen.com/english/advisories/2009/3316
- http://secunia.com/advisories/35847