CVE-2009-2847

The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from the kernel stack via the sigaltstack function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
linuxkernel
2.6.24.7
linuxkernel
2.6.25.15
linuxlinux_kernel
𝑥
≤ 2.6.16.31
linuxlinux_kernel
2.6
linuxlinux_kernel
2.6.0
linuxlinux_kernel
2.6.1
linuxlinux_kernel
2.6.10
linuxlinux_kernel
2.6.11
linuxlinux_kernel
2.6.11.1
linuxlinux_kernel
2.6.11.2
linuxlinux_kernel
2.6.11.3
linuxlinux_kernel
2.6.11.4
linuxlinux_kernel
2.6.11.5
linuxlinux_kernel
2.6.11.6
linuxlinux_kernel
2.6.11.7
linuxlinux_kernel
2.6.11.8
linuxlinux_kernel
2.6.11.9
linuxlinux_kernel
2.6.11.10
linuxlinux_kernel
2.6.11.11
linuxlinux_kernel
2.6.11.12
linuxlinux_kernel
2.6.12
linuxlinux_kernel
2.6.12.1
linuxlinux_kernel
2.6.12.2
linuxlinux_kernel
2.6.12.3
linuxlinux_kernel
2.6.12.4
linuxlinux_kernel
2.6.12.5
linuxlinux_kernel
2.6.12.6
linuxlinux_kernel
2.6.13
linuxlinux_kernel
2.6.13.1
linuxlinux_kernel
2.6.13.2
linuxlinux_kernel
2.6.13.3
linuxlinux_kernel
2.6.13.4
linuxlinux_kernel
2.6.13.5
linuxlinux_kernel
2.6.14
linuxlinux_kernel
2.6.14.1
linuxlinux_kernel
2.6.14.2
linuxlinux_kernel
2.6.14.3
linuxlinux_kernel
2.6.14.4
linuxlinux_kernel
2.6.14.5
linuxlinux_kernel
2.6.14.6
linuxlinux_kernel
2.6.14.7
linuxlinux_kernel
2.6.15
linuxlinux_kernel
2.6.15.1
linuxlinux_kernel
2.6.15.2
linuxlinux_kernel
2.6.15.3
linuxlinux_kernel
2.6.15.4
linuxlinux_kernel
2.6.15.5
linuxlinux_kernel
2.6.15.6
linuxlinux_kernel
2.6.15.7
linuxlinux_kernel
2.6.16
linuxlinux_kernel
2.6.16.1
linuxlinux_kernel
2.6.16.2
linuxlinux_kernel
2.6.16.3
linuxlinux_kernel
2.6.16.10
linuxlinux_kernel
2.6.16.11
linuxlinux_kernel
2.6.16.12
linuxlinux_kernel
2.6.16.13
linuxlinux_kernel
2.6.16.14
linuxlinux_kernel
2.6.16.15
linuxlinux_kernel
2.6.16.16
linuxlinux_kernel
2.6.16.17
linuxlinux_kernel
2.6.16.18
linuxlinux_kernel
2.6.16.19
linuxlinux_kernel
2.6.16.20
linuxlinux_kernel
2.6.16.21
linuxlinux_kernel
2.6.16.22
linuxlinux_kernel
2.6.16.23
linuxlinux_kernel
2.6.16.24
linuxlinux_kernel
2.6.16.25
linuxlinux_kernel
2.6.16.26
linuxlinux_kernel
2.6.16.27
linuxlinux_kernel
2.6.16.28
linuxlinux_kernel
2.6.16.29
linuxlinux_kernel
2.6.16.30
linuxlinux_kernel
2.6.16.31
linuxlinux_kernel
2.6.16.31:-rc1
linuxlinux_kernel
2.6.16.31:-rc2
linuxlinux_kernel
2.6.16.31:-rc3
linuxlinux_kernel
2.6.16.31:-rc4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
jaunty
Fixed 2.6.28-16.55
released
intrepid
Fixed 2.6.27-15.43
released
hardy
Fixed 2.6.24-25.63
released
dapper
dne
linux-source-2.6.15
jaunty
dne
intrepid
dne
hardy
dne
dapper
Fixed 2.6.15-55.80
released
References