CVE-2009-2903
published 2009-09-15CVE-2009-2903: Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but…
PriorityP428high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
3.85%
89.0th percentile
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| linux | linux_kernel | 2.4.0 – 2.4.37.6 | — |
| linux | linux_kernel | 2.6.0 – 2.6.31 | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat7.1HIGH
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-10-22·CVSS 4.4
CVE-2009-3238 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Solar Designer discovered that the z90crypt driver did not correctly
check capabilities. A local attacker could exploit this to shut down
the device, leading to a denial of service. Only affected Ubuntu 6.06.
(CVE-2009-1883)
Michael Buesch discovered that the SGI GRU driver did not correctly check
the length when setting options. A local attacker could exploit this
to write to the kernel stack, leading to root privilege escalation or
a denial of service. Only affected Ubuntu 8.10 and 9.04. (CVE-2009-2584)
It was discovered that SELinux did not fully implement the mmap_min_addr
restrictions. A local attacker could exploit this to allocate the
NULL memory page which could lead to further attacks against kernel
NULL
Red Hat
kernel: appletalk: denial of service when handling IP tunnelled over DDP datagrams
vendor_redhat·2009-09-11·CVSS 7.1
CVE-2009-2903 [HIGH] CWE-772 kernel: appletalk: denial of service when handling IP tunnelled over DDP datagrams
kernel: appletalk: denial of service when handling IP tunnelled over DDP datagrams
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
Statement: Red Hat is aware of this issue. Please see https://access.redhat.com/articles/19069
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5, as the affected driver is not enabled in these kernels. The affected driver is available in Red Hat Enterprise MRG. It is also available in Red Hat Enterprise Linux 3, but only if the kernel-unsupported package is installed.
GHSA
GHSA-q9qh-2r93-gfjh: Memory leak in the appletalk subsystem in the Linux kernel 2
ghsa_unreviewed·2022-05-02
CVE-2009-2903 [HIGH] CWE-772 GHSA-q9qh-2r93-gfjh: Memory leak in the appletalk subsystem in the Linux kernel 2
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/davem/net-next-2.6.git%3Ba=commit%3Bh=ffcfb8db540ff879c2a85bf7e404954281443414http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.htmlhttp://secunia.com/advisories/36707http://secunia.com/advisories/37105http://secunia.com/advisories/37909http://www.mandriva.com/security/advisories?name=MDVSA-2009:329http://www.openwall.com/lists/oss-security/2009/09/14/1http://www.openwall.com/lists/oss-security/2009/09/14/2http://www.openwall.com/lists/oss-security/2009/09/17/11http://www.securityfocus.com/bid/36379http://www.ubuntu.com/usn/USN-852-1https://bugzilla.redhat.com/show_bug.cgi?id=522331http://git.kernel.org/?p=linux/kernel/git/davem/net-next-2.6.git%3Ba=commit%3Bh=ffcfb8db540ff879c2a85bf7e404954281443414http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.htmlhttp://secunia.com/advisories/36707http://secunia.com/advisories/37105http://secunia.com/advisories/37909http://www.mandriva.com/security/advisories?name=MDVSA-2009:329http://www.openwall.com/lists/oss-security/2009/09/14/1http://www.openwall.com/lists/oss-security/2009/09/14/2http://www.openwall.com/lists/oss-security/2009/09/17/11http://www.securityfocus.com/bid/36379http://www.ubuntu.com/usn/USN-852-1https://bugzilla.redhat.com/show_bug.cgi?id=522331
2009-09-15
Published