CVE-2009-1385
published 2009-06-04CVE-2009-1385: Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e…
PriorityP345high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
33.49%
98.2th percentile
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
Affected
128 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| intel | e1000 | <= 7.4.35 | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
| intel | e1000 | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.8HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: e1000 issue reported at 26c3
vendor_redhat·2009-12-28·CVSS 7.8
CVE-2009-4536 [HIGH] kernel: e1000 issue reported at 26c3
kernel: e1000 issue reported at 26c3
drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-07-02·CVSS 4.9
CVE-2009-1242 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Igor Zhbanov discovered that NFS clients were able to create device nodes
even when root_squash was enabled. An authenticated remote attacker
could create device nodes with open permissions, leading to a loss of
privacy or escalation of privileges. Only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1072)
Dan Carpenter discovered that SELinux did not correctly handle
certain network checks when running with compat_net=1. A local
attacker could exploit this to bypass network checks. Default Ubuntu
installations do not enable SELinux, and only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1184)
Shaohua Li discovered that memory was not correctly initialized in the
AGP subsystem. A local attacker could potentially re
Red Hat
kernel: e1000_clean_rx_irq() denial of service
vendor_redhat·2007-04-25·CVSS 7.8
CVE-2009-1385 [HIGH] CWE-190 kernel: e1000_clean_rx_irq() denial of service
kernel: e1000_clean_rx_irq() denial of service
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
GHSA
GHSA-f8hp-66pw-jmc7: drivers/net/e1000/e1000_main
ghsa_unreviewed·2022-05-02·CVSS 7.8
CVE-2009-4536 [HIGH] GHSA-f8hp-66pw-jmc7: drivers/net/e1000/e1000_main
drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.
GHSA
GHSA-pp2r-wqw2-9r3r: Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main
ghsa_unreviewed·2022-05-02
CVE-2009-1385 [HIGH] GHSA-pp2r-wqw2-9r3r: Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-4536 kernel: e1000 issue reported at 26c3
bugzilla·2010-01-04·CVSS 7.8
CVE-2009-4536 [HIGH] CVE-2009-4536 kernel: e1000 issue reported at 26c3
CVE-2009-4536 kernel: e1000 issue reported at 26c3
Description of problem:
This was disclosed at 26c3.
Fabian mentioned that CVE-2009-1385 has an incorrect fix. The fix he points to
is http://git.kernel.org/linus/ea30e11970a96cfe5e32c03a29332554573b4a10
Which fixes a DoS when the frame spans multiple buffers and the last buffer
contains less than four bytes. However, if that last fragment is longer than 4
bytes, it will actually be taken into account while the previous fragments will
have been ignored. This means we can end up in a situation where a single
Ethernet frame has multiple interpretation since at some level it will be
considered as a whole and in others the N first bytes will be silently
discarded.
References:
http://events.ccc.de/congress/2009/Fahrplan//events/3596.en.html
Bugzilla
CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service
bugzilla·2009-05-28·CVSS 7.8
CVE-2009-1385 [HIGH] CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service
CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service
This bug was fixed in http://sourceforge.net/projects/e1000 since release 7.5.5 (2007-04-25 22:15), but not in upstream kernel.
http://sourceforge.net/project/shownotes.php?release_id=504022&group_id=42302
Notes:
* fix panic on changing MTU under stress
Discussion:
Patch to fix bad length checking in e1000. E1000 by default does two things:
1) Spans rx descriptors for packets that don't fit into 1 skb on recieve
2) Strips the crc from a frame by subtracting 4 bytes from the length prior to doing an skb_put
Since the e1000 driver isn't written to support receiving packets that span multiple rx buffers, it checks the End of Packet bit of every frame, and discards it if its not set. This places us in a situation where, if we h
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ea30e11970a96cfe5e32c03a29332554573b4a10http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.htmlhttp://osvdb.org/54892http://secunia.com/advisories/35265http://secunia.com/advisories/35566http://secunia.com/advisories/35623http://secunia.com/advisories/35656http://secunia.com/advisories/35847http://secunia.com/advisories/36051http://secunia.com/advisories/36131http://secunia.com/advisories/36327http://secunia.com/advisories/37471http://sourceforge.net/project/shownotes.php?release_id=504022&group_id=42302http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1865http://www.intel.com/support/network/sb/CS-030543.htmhttp://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8http://www.mandriva.com/security/advisories?name=MDVSA-2009:135http://www.mandriva.com/security/advisories?name=MDVSA-2009:148http://www.openwall.com/lists/oss-security/2009/06/03/2http://www.redhat.com/support/errata/RHSA-2009-1157.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1193.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/archive/1/512019/100/0/threadedhttp://www.securityfocus.com/bid/35185http://www.ubuntu.com/usn/usn-793-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://bugzilla.redhat.com/show_bug.cgi?id=502981https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11598https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11681https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8340https://rhn.redhat.com/errata/RHSA-2009-1550.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ea30e11970a96cfe5e32c03a29332554573b4a10http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.htmlhttp://osvdb.org/54892http://secunia.com/advisories/35265http://secunia.com/advisories/35566http://secunia.com/advisories/35623http://secunia.com/advisories/35656http://secunia.com/advisories/35847http://secunia.com/advisories/36051http://secunia.com/advisories/36131http://secunia.com/advisories/36327http://secunia.com/advisories/37471http://sourceforge.net/project/shownotes.php?release_id=504022&group_id=42302http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1865http://www.intel.com/support/network/sb/CS-030543.htmhttp://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8http://www.mandriva.com/security/advisories?name=MDVSA-2009:135http://www.mandriva.com/security/advisories?name=MDVSA-2009:148http://www.openwall.com/lists/oss-security/2009/06/03/2http://www.redhat.com/support/errata/RHSA-2009-1157.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1193.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/archive/1/512019/100/0/threadedhttp://www.securityfocus.com/bid/35185http://www.ubuntu.com/usn/usn-793-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://bugzilla.redhat.com/show_bug.cgi?id=502981https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11598https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11681https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8340https://rhn.redhat.com/errata/RHSA-2009-1550.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.html
2009-06-04
Published