kernel: tc: uninitialised kernel memory leak
Published Oct 19, 2009
2.1
LOWCVSS 2.0
EPSS 0.40%
Description
The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.
Affected products
No data.
Configuration 1
- ≥ 2.4.0 · < 2.4.37.6
- ≥ 2.6.0 · < 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
Configuration 2
- 6.06
- 8.04
- 8.10
- 9.04
- 9.10
Configuration 3
- 5.0
- 5.4
- 5.0
- 5.0
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-137.el5rt
Fixed · RHSA-2009:1540
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.0.15.EL
Fixed · RHSA-2009:1522
Red Hat Enterprise Linux 5
kernel-0:2.6.18-164.6.1.el5
Fixed · RHSA-2009:1548
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-137.el5rt | Fixed | RHSA-2009:1540 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.0.15.EL | Fixed | RHSA-2009:1522 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-164.6.1.el5 | Fixed | RHSA-2009:1548 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.40% (0.00397) | 31.49th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.40% (0.00397) | 31.26th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00077) | 20.57th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (28)
- http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git%3Ba=commit%3Bh=096ed17f20affc2db0e307658c69b67433992a7a x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=16ebb5e0b36ceadc8186f71d68b0c4fa4b6e781b x_refsource_CONFIRM
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLISTThird Party Advisory
- http://patchwork.ozlabs.org/patch/32830/ x_refsource_CONFIRMPatchThird Party Advisory
- http://secunia.com/advisories/37084 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38834 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.6 x_refsource_CONFIRMBroken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.31/ChangeLog-2.6.31-rc9 x_refsource_CONFIRMBroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:198 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/03/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/05/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/06/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/07/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/17/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/17/9 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1522.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securitytracker.com/id?1023073 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-864-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-3228 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=520990 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3228
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6757 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9409 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1540.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1548.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-3228
Change history (0)
No recorded changes yet.