CVE-2009-2406

Linux kernel <2.6.30.4 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to not ensuring that the key signature length in a Tag 11 packet is compatible with the key signature buffer size.

References (27)

... and 7 more

Scores

EPSS 0.0031
EPSS Percentile 54.2%

Classification

CWE
CWE-119
Status draft

Affected Products (50)

linux/kernel
linux/kernel
linux/linux_kernel < 2.6.30.3
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Jul 31, 2009
Tracked Since Feb 18, 2026