CVE-2009-1265

Linux Kernel < 2.6.30-rc1 - Information Disclosure via rose_sendmsg Integer Overflow

Title source: llm
STIX 2.1

Description

Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.

References (25)

Core 25
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35390
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:135
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/53630
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35656
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1794
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/53571
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35185
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35011
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34654
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/04/08/2
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-793-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/53631
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34981
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1800
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35387
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1787
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:119
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35121
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35394

Scores

EPSS 0.0317
EPSS Percentile 86.8%

Details

CWE
CWE-189
Status published
Products (50)
linux/linux_kernel 2.6.24.4
linux/linux_kernel 2.6.24.5
linux/linux_kernel 2.6.24.6
linux/linux_kernel 2.6.24.7
linux/linux_kernel 2.6.25
linux/linux_kernel 2.6.25.1
linux/linux_kernel 2.6.25.2
linux/linux_kernel 2.6.25.3
linux/linux_kernel 2.6.25.4
linux/linux_kernel 2.6.25.5
... and 40 more
Published Apr 08, 2009
Tracked Since Feb 18, 2026