CVE-2009-3228
19.10.2009, 20:00
The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 2.4.0 ≤ 𝑥 < 2.4.37.6 |
linux | linux_kernel | 2.6.0 ≤ 𝑥 < 2.6.31 |
linux | linux_kernel | 2.6.31 |
linux | linux_kernel | 2.6.31:rc1 |
linux | linux_kernel | 2.6.31:rc2 |
linux | linux_kernel | 2.6.31:rc3 |
linux | linux_kernel | 2.6.31:rc4 |
linux | linux_kernel | 2.6.31:rc5 |
linux | linux_kernel | 2.6.31:rc6 |
linux | linux_kernel | 2.6.31:rc7 |
linux | linux_kernel | 2.6.31:rc8 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
canonical | ubuntu_linux | 9.10 |
redhat | enterprise_linux_desktop | 5.0 |
redhat | enterprise_linux_eus | 5.4 |
redhat | enterprise_linux_server | 5.0 |
redhat | enterprise_linux_workstation | 5.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References