Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent
Published Apr 8, 2009
5.0
MEDIUMCVSS 2.0
EPSS 3.17%
Description
Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.
Affected products
No data.
- 2.6.24.4
- 2.6.24.5
- 2.6.24.6
- 2.6.24.7
- 2.6.25
- 2.6.25.1
- 2.6.25.2
- 2.6.25.3
- 2.6.25.4
- 2.6.25.5
- 2.6.25.6
- 2.6.25.7
- 2.6.25.8
- 2.6.25.9
- 2.6.25.10
- 2.6.25.11
- 2.6.25.12
- 2.6.25.13
- 2.6.25.14
- 2.6.25.15
- 2.6.25.16
- 2.6.25.17
- 2.6.25.18
- 2.6.25.19
- 2.6.25.20
- 2.6.26
- 2.6.26.1
- 2.6.26.2
- 2.6.26.3
- 2.6.26.4
- 2.6.26.5
- 2.6.26.6
- 2.6.26.7
- 2.6.27
- 2.6.27.1
- 2.6.27.2
- 2.6.27.3
- 2.6.27.4
- 2.6.27.5
- 2.6.27.6
- 2.6.27.7
- 2.6.27.8
- 2.6.27.9
- 2.6.27.10
- 2.6.27.11
- 2.6.27.12
- 2.6.27.13
- 2.6.27.14
- 2.6.27.15
- 2.6.27.16
- 2.6.27.17
- 2.6.27.18
- 2.6.27.19
- 2.6.27.20
- 2.6.27.21
- 2.6.27.22
- 2.6.27.23
- 2.6.27.24
- 2.6.27.25
- 2.6.27.26
- 2.6.27.27
- 2.6.27.28
- 2.6.27.29
- 2.6.27.30
- 2.6.27.31
- 2.6.27.32
- 2.6.27.33
- 2.6.27.34
- 2.6.27.35
- 2.6.27.36
- 2.6.27.37
- 2.6.27.38
- 2.6.27.39
- 2.6.27.40
- 2.6.27.41
- 2.6.27.42
- 2.6.27.43
- 2.6.27.44
- 2.6.27.45
- 2.6.27.46
- 2.6.27.47
- 2.6.27.48
- 2.6.27.49
- 2.6.27.50
- 2.6.27.51
- 2.6.27.52
- 2.6.27.53
- 2.6.27.54
- 2.6.27.55
- 2.6.27.56
- 2.6.27.57
- 2.6.27.58
- 2.6.27.59
- 2.6.27.60
- 2.6.27.61
- 2.6.27.62
- 2.6.28
- 2.6.28.1
- 2.6.28.2
- 2.6.28.3
- 2.6.28.4
- 2.6.28.5
- 2.6.28.6
- 2.6.28.7
- 2.6.28.8
- 2.6.28.9
- 2.6.28.10
- 2.6.29
- 2.6.29.1
- 2.6.29.2
- 2.6.29.3
- 2.6.29.4
- 2.6.29.5
- 2.6.29.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 4, 5, or Red Hat Enterprise MRG, as the affected driver is not enabled in these kernels. The affected driver is available in Red Hat Enterprise Linux 3, but only if the kernel-unsupported package is installed. This issue has been rated as having moderate security impact as it does not lead to a denial of service or privilege escalation. As Red Hat Enterprise Linux 3 is now in Production 3 of its maintenance life-cycle, http://www.redhat.com/security/updates/errata, and the affected driver can only be enabled when using the unsupported kernel-unsupported package, a fix for this issue is not currently planned to be included in the future updates.
References (28)
- http://bugzilla.kernel.org/show_bug.cgi?id=10423 x_refsource_MISCExploit
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=83e0bbcbe2145f160fbaa109b0439dae7f4a38a9 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/53571 vdb-entryx_refsource_OSVDB
- http://osvdb.org/53630 vdb-entryx_refsource_OSVDB
- http://osvdb.org/53631 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/34981 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35011 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35121 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35185 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35387 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35390 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35394 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35656 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2009/dsa-1787 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2009/dsa-1794 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2009/dsa-1800 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:119 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:135 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2009/04/08/2 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/34654 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-793-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2009-1265 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1265
- https://www.cve.org/CVERecord?id=CVE-2009-1265
Change history (0)
No recorded changes yet.