CVE-2009-1389
published 2009-06-16CVE-2009-1389: Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
5.47%
91.9th percentile
Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
Affected
262 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| linux | kernel | — | — |
| linux | kernel | — | — |
| linux | linux_kernel | <= 2.6.32.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: r8169 issue reported at 26c3
vendor_redhat·2009-12-28·CVSS 7.8
CVE-2009-4537 [HIGH] CWE-682 kernel: r8169 issue reported at 26c3
kernel: r8169 issue reported at 26c3
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-07-28·CVSS 7.8
CVE-2009-1389 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Michael Tokarev discovered that the RTL8169 network driver did not
correctly validate buffer sizes. A remote attacker on the local network
could send specially crafted traffic that would crash the system or
potentially grant elevated privileges. (CVE-2009-1389)
Julien Tinnes and Tavis Ormandy discovered that when executing setuid
processes the kernel did not clear certain personality flags. A local
attacker could exploit this to map the NULL memory page, causing other
vulnerabilities to become exploitable. Ubuntu 6.06 was not affected.
(CVE-2009-1895)
Matt T. Yourst discovered that KVM did not correctly validate the
page table root. A local attacker could exploit this to crash the
system, leading to a denial of s
Red Hat
kernel: r8169: fix crash when large packets are received
vendor_redhat·2009-02-14·CVSS 7.8
CVE-2009-1389 [HIGH] kernel: r8169: fix crash when large packets are received
kernel: r8169: fix crash when large packets are received
Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
GHSA
GHSA-g3p7-2p6v-2v85: Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169
ghsa_unreviewed·2022-05-02
CVE-2009-1389 [HIGH] CWE-119 GHSA-g3p7-2p6v-2v85: Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169
Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
GHSA
GHSA-pvpv-c389-c5f8: drivers/net/r8169
ghsa_unreviewed·2022-05-02·CVSS 7.8
CVE-2009-4537 [HIGH] CWE-20 GHSA-pvpv-c389-c5f8: drivers/net/r8169
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-4537 kernel: r8169 issue reported at 26c3
bugzilla·2009-12-28·CVSS 7.8
CVE-2009-4537 [HIGH] CVE-2009-4537 kernel: r8169 issue reported at 26c3
CVE-2009-4537 kernel: r8169 issue reported at 26c3
Description of problem:
This was disclosed at 26c3.
Fabian also mentioned the fix for CVE-2009-1389 regarding the r8169 driver introduces a similar security problem as this: http://git.kernel.org/linus/fdd7b4c3302c93f6833e338903ea77245eb510b4
- RTL_W16(RxMaxSize, 16383);
+ RTL_W16(RxMaxSize, rx_buf_sz);
is actually a revert of this:
http://git.kernel.org/linus/126fa4b9ca5d9d7cb7d46f779ad3bd3631ca387c
- /* For gigabit rtl8169, MTU + header + CRC + VLAN */
- RTL_W16(RxMaxSize, tp->rx_buf_sz);
+ /* Low hurts. Let's disable the filtering. */
+ RTL_W16(RxMaxSize, 16383);
The accompanying comment for the original commit (126fa):
The size of the incoming frame is not correctly checked.
The RxMaxSize register (0xDA) does not work as expect
Bugzilla
CVE-2009-1389 kernel: r8169: fix crash when large packets are received
bugzilla·2009-06-09·CVSS 7.8
CVE-2009-1389 [HIGH] CVE-2009-1389 kernel: r8169: fix crash when large packets are received
CVE-2009-1389 kernel: r8169: fix crash when large packets are received
Created attachment 346959
backtraces
Description of problem:
Michael Tokarev reported receiving a large packet could crash a machine with RTL8169 NIC.
Problem is this driver tells that NIC frames up to 16383 bytes can be received but provides skb to rx ring allocated with smaller sizes (1536 bytes in case standard 1500 bytes MTU is used)
When a frame larger than what was allocated by driver is received, dma transfert can occurs past the end of buffer and corrupt kernel memory.
Fix is to tell to NIC what is the maximum size a frame can be.
References:
http://marc.info/?t=123462473200002
http://lkml.org/lkml/2009/6/8/194
http://www.corpit.ru/mjt/r8169-mtu-oops.jpg
http://article.gmane.org/gmane.linux.network/130114
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=fdd7b4c3302c93f6833e338903ea77245eb510b4http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.htmlhttp://lkml.org/lkml/2009/6/8/194http://marc.info/?l=linux-netdev&m=123462461713724&w=2http://secunia.com/advisories/35265http://secunia.com/advisories/35566http://secunia.com/advisories/35847http://secunia.com/advisories/36045http://secunia.com/advisories/36051http://secunia.com/advisories/36131http://secunia.com/advisories/36327http://secunia.com/advisories/37298http://secunia.com/advisories/37471http://secunia.com/advisories/40645http://support.avaya.com/css/P8/documents/100067254http://support.citrix.com/article/CTX123453http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1865http://www.mandriva.com/security/advisories?name=MDVSA-2009:148http://www.openwall.com/lists/oss-security/2009/06/10/1http://www.redhat.com/support/errata/RHSA-2009-1157.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1193.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/35281http://www.securitytracker.com/id?1023507http://www.ubuntu.com/usn/usn-807-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316http://www.vupen.com/english/advisories/2010/0219http://www.vupen.com/english/advisories/2010/1857https://bugzilla.redhat.com/show_bug.cgi?id=504726https://exchange.xforce.ibmcloud.com/vulnerabilities/51051https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10415https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8108https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=fdd7b4c3302c93f6833e338903ea77245eb510b4http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.htmlhttp://lkml.org/lkml/2009/6/8/194http://marc.info/?l=linux-netdev&m=123462461713724&w=2http://secunia.com/advisories/35265http://secunia.com/advisories/35566http://secunia.com/advisories/35847http://secunia.com/advisories/36045http://secunia.com/advisories/36051http://secunia.com/advisories/36131http://secunia.com/advisories/36327http://secunia.com/advisories/37298http://secunia.com/advisories/37471http://secunia.com/advisories/40645http://support.avaya.com/css/P8/documents/100067254http://support.citrix.com/article/CTX123453http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1865http://www.mandriva.com/security/advisories?name=MDVSA-2009:148http://www.openwall.com/lists/oss-security/2009/06/10/1http://www.redhat.com/support/errata/RHSA-2009-1157.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1193.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/35281http://www.securitytracker.com/id?1023507http://www.ubuntu.com/usn/usn-807-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316http://www.vupen.com/english/advisories/2010/0219http://www.vupen.com/english/advisories/2010/1857https://bugzilla.redhat.com/show_bug.cgi?id=504726https://exchange.xforce.ibmcloud.com/vulnerabilities/51051https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10415https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8108https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.html
2009-06-16
Published