CVE-2009-2407

Linux kernel <2.6.30.4 - Buffer Overflow

Title source: llm

Description

Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.

References (25)

... and 5 more

Scores

EPSS 0.0028
EPSS Percentile 51.1%

Classification

CWE
CWE-119
Status draft

Affected Products (50)

linux/linux_kernel < 2.6.30.3
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Jul 31, 2009
Tracked Since Feb 18, 2026