CVE-2009-3228

Advisory lineage Upstream: 0 Downstream: 6
Modified
Published: 19 Oct 2009, 19:27
Last modified:07 Aug 2024, 06:22

Vulnerability Summary

Overall Risk (default)
minimal
8/100
CVSS Score
2.1 LOW
v2.0 (nvd)
EPSS Score
0.08% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Oct 2009, 19:27
Published
Vulnerability first disclosed
07 Aug 2024, 06:22
Last Modified
Vulnerability information updated

Description

The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.

CVSS Metrics

  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.08% Percentile: 23%

Techniques & Countermeasures

  • CWE-909Missing Initialization of Resource

    The product does not initialize a critical resource.

Affected Systems

  • canonicalubuntu_linux

    6.06 | 8.04 | 8.10 | 9.04 | 9.10

  • linuxlinux_kernel

    ≥ 2.4.0, < 2.4.37.6 | ≥ 2.6.0, < 2.6.31 | 2.6.31 | 2.6.31:rc1 | 2.6.31:rc2 | 2.6.31:rc3 | 2.6.31:rc4 | 2.6.31:rc5 | 2.6.31:rc6 | 2.6.31:rc7 | 2.6.31:rc8

  • redhatenterprise_linux_desktop

    5.0

  • redhatenterprise_linux_eus

    5.4

  • redhatenterprise_linux_server

    5.0

  • redhatenterprise_linux_workstation

    5.0

References (25)