CVE-2009-3228

Linux Kernel <2.4.37.6 & <2.6.31-rc9 - Info Disclosure

Title source: llm
STIX 2.1

Description

The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.

References (25)

Core 25
Core References
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/09/17/9
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/09/17/1
Third Party Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1540.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-864-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38794
Third Party Advisory mailing-list x_refsource_mlist
http://lists.vmware.com/pipermail/security-announce/2010/000082.html
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:198
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/09/03/1
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=520990
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37084
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1522.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-1548.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38834
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/09/06/2
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/09/07/2
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/09/05/2
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023073
Patch, Third Party Advisory x_refsource_confirm
http://patchwork.ozlabs.org/patch/32830/
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0528

Scores

EPSS 0.0040
EPSS Percentile 31.3%

Details

CWE
CWE-909
Status published
Products (11)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
canonical/ubuntu_linux 9.04
canonical/ubuntu_linux 9.10
linux/linux_kernel 2.6.31 (9 CPE variants)
linux/linux_kernel 2.4.0 - 2.4.37.6
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_eus 5.4
redhat/enterprise_linux_server 5.0
... and 1 more
Published Oct 19, 2009
Tracked Since Feb 18, 2026