CVE-2009-3612
19.10.2009, 20:00
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 ≤ 2.4.37.6 |
linux | linux_kernel | 2.6.0 ≤ 𝑥 < 2.6.32 |
linux | linux_kernel | 2.6.32 |
linux | linux_kernel | 2.6.32:rc1 |
linux | linux_kernel | 2.6.32:rc2 |
linux | linux_kernel | 2.6.32:rc3 |
linux | linux_kernel | 2.6.32:rc4 |
opensuse | opensuse | 11.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
canonical | ubuntu_linux | 9.10 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References