CVE-2009-0322
published 2009-01-28CVE-2009-0322: drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash)…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.50%
40.1th percentile
drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.27.13 | 2.6.27.13 |
| linux | linux_kernel | >= 2.6.28 < 2.6.28.2 | 2.6.28.2 |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat4.9MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fmg5-3x35-8gfc: drivers/firmware/dell_rbu
ghsa_unreviewed·2022-05-02
CVE-2009-0322 [MEDIUM] GHSA-fmg5-3x35-8gfc: drivers/firmware/dell_rbu
drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-04-07·CVSS 4.0
CVE-2009-0029 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
NFS did not correctly handle races between fcntl and interrupts. A local
attacker on an NFS mount could consume unlimited kernel memory, leading to
a denial of service. (CVE-2008-4307)
Sparc syscalls did not correctly check mmap regions. A local attacker could
cause a system panic, leading to a denial of service. (CVE-2008-6107)
In certain situations, cloned processes were able to send signals to parent
processes, crossing privilege boundaries. A local attacker could send
arbitrary signals to parent processes, leading to a denial of service.
(CVE-2009-0028)
The 64-bit syscall interfaces did not correctly handle sign extension. A
local attacker could make malicious syscalls, possibly gaining root
privileges. The
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-04-06·CVSS 4.0
CVE-2008-4307 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
NFS did not correctly handle races between fcntl and interrupts. A local
attacker on an NFS mount could consume unlimited kernel memory, leading to
a denial of service. Ubuntu 8.10 was not affected. (CVE-2008-4307)
Sparc syscalls did not correctly check mmap regions. A local attacker
could cause a system panic, leading to a denial of service. Ubuntu 8.10
was not affected. (CVE-2008-6107)
In certain situations, cloned processes were able to send signals to parent
processes, crossing privilege boundaries. A local attacker could send
arbitrary signals to parent processes, leading to a denial of service.
(CVE-2009-0028)
The kernel keyring did not free memory correctly. A local attacker could
consume unlimited kernel
Red Hat
kernel: dell_rbu local oops
vendor_redhat·2009-01-17·CVSS 4.9
CVE-2009-0322 [MEDIUM] kernel: dell_rbu local oops
kernel: dell_rbu local oops
drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=81156928f8fe31621e467490b9d441c0285998c3http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.13http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.2http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://secunia.com/advisories/33656http://secunia.com/advisories/33758http://secunia.com/advisories/34252http://secunia.com/advisories/34394http://secunia.com/advisories/34502http://secunia.com/advisories/34680http://secunia.com/advisories/34762http://secunia.com/advisories/34981http://secunia.com/advisories/35011http://secunia.com/advisories/35390http://secunia.com/advisories/35394http://secunia.com/advisories/37471http://support.avaya.com/elmodocs2/security/ASA-2009-114.htmhttp://www.debian.org/security/2009/dsa-1749http://www.debian.org/security/2009/dsa-1787http://www.debian.org/security/2009/dsa-1794http://www.redhat.com/support/errata/RHSA-2009-0326.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0331.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0360.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/33428http://www.ubuntu.com/usn/usn-751-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10163https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7734http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=81156928f8fe31621e467490b9d441c0285998c3http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.13http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.2http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://secunia.com/advisories/33656http://secunia.com/advisories/33758http://secunia.com/advisories/34252http://secunia.com/advisories/34394http://secunia.com/advisories/34502http://secunia.com/advisories/34680http://secunia.com/advisories/34762http://secunia.com/advisories/34981http://secunia.com/advisories/35011http://secunia.com/advisories/35390http://secunia.com/advisories/35394http://secunia.com/advisories/37471http://support.avaya.com/elmodocs2/security/ASA-2009-114.htmhttp://www.debian.org/security/2009/dsa-1749http://www.debian.org/security/2009/dsa-1787http://www.debian.org/security/2009/dsa-1794http://www.redhat.com/support/errata/RHSA-2009-0326.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0331.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0360.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/33428http://www.ubuntu.com/usn/usn-751-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10163https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7734
2009-01-28
Published