CVE-2009-3080

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.31.6
linuxlinux_kernel
2.6.32
linuxlinux_kernel
2.6.32:rc1
linuxlinux_kernel
2.6.32:rc3
linuxlinux_kernel
2.6.32:rc4
linuxlinux_kernel
2.6.32:rc5
opensuseopensuse
11.1
opensuseopensuse
11.2
debiandebian_linux
4.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
canonicalubuntu_linux
9.10
vmwareesx
3.5
redhatvirtualization
5.0
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_eus
5.4
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server_workstation
5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
karmic
Fixed 2.6.31-16.52
released
jaunty
Fixed 2.6.28-17.58
released
intrepid
Fixed 2.6.27-16.44
released
hardy
Fixed 2.6.24-26.64
released
dapper
dne
linux-source-2.6.15
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
Fixed 2.6.15-55.81
released
References