CVE-2009-4536

EUVD-2009-4502
drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 2.6.32.3
debiandebian_linux
4.0
debiandebian_linux
5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
dapper
dne
hardy
Fixed 2.6.24-27.65
released
intrepid
Fixed 2.6.27-17.45
released
jaunty
Fixed 2.6.28-18.59
released
karmic
Fixed 2.6.31-19.56
released
linux-source-2.6.15
dapper
Fixed 2.6.15-55.82
released
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
Common Weakness Enumeration
References