kernel: ecryptfs file header infoleak
Published Mar 25, 2009
4.9
MEDIUMCVSS 2.0
EPSS 0.39%
Description
The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows local users to obtain portions of kernel memory.
Affected products
No data.
- 2.6.28
- 2.6.28.1
- 2.6.28.2
- 2.6.28.3
- 2.6.28.4
- 2.6.28.5
- 2.6.28.6
- 2.6.28.7
- 2.6.28.8
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-128.1.10.el5
Fixed · RHSA-2009:0473
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-128.1.10.el5 | Fixed | RHSA-2009:0473 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and Red Hat Enterprise MRG.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.39% (0.00389) | 30.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.39% (0.00389) | 30.44th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00076) | 20.29th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (20)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=8faece5f906725c10e7a1f6caf84452abadbdc7b x_refsource_CONFIRM
- http://osvdb.org/52860 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2009-0473.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/34422 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35015 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37471 third-party-advisoryx_refsource_SECUNIA
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/34216 vdb-entryx_refsource_BIDPatch
- http://www.securitytracker.com/id?1022177 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2009/0802 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-0787 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=491254 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49355 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-0787
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11068 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8319 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-0787
Change history (0)
No recorded changes yet.