CVE-2009-3080
published 2009-11-20CVE-2009-3080: Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service…
PriorityP426high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.42%
33.8th percentile
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | <= 2.6.31.6 | — |
| linux | linux_kernel | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_workstation | — | — |
| redhat | fedora | — | — |
| redhat | virtualization | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| vmware | esx | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware hosted product updates, ESX patches and VI Client update resolve multiple security issues
vendor_vmware·2011-06-02·CVSS 7.8
CVE-2009-3080 [HIGH] VMware hosted product updates, ESX patches and VI Client update resolve multiple security issues
VMSA-2011-0009: VMware hosted product updates, ESX patches and VI Client update resolve multiple security issues
a. VMware vmkernel third party e1000(e) Driver Packet Filter Bypass There is an issue in the e1000(e) Linux driver for Intel PRO/1000 adapters that allows a remote attacker to bypass packet filters. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-4536 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= vCenter Product Version ======= any Running on ======= Windows Replace with/ Apply Patch ===
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-12-05·CVSS 4.9
CVE-2009-3726 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the AX.25 network subsystem did not correctly
check integer signedness in certain setsockopt calls. A local attacker
could exploit this to crash the system, leading to a denial of service.
Ubuntu 9.10 was not affected. (CVE-2009-2909)
Jan Beulich discovered that the kernel could leak register contents to
32-bit processes that were switched to 64-bit mode. A local attacker
could run a specially crafted binary to read register values from an
earlier process, leading to a loss of privacy. (CVE-2009-2910)
Dave Jones discovered that the gdth SCSI driver did not correctly validate
array indexes in certain ioctl calls. A local attacker could exploit
this to crash the system or gain elevated privil
Red Hat
kernel: gdth: Prevent negative offsets in ioctl
vendor_redhat·2009-11-20·CVSS 7.2
CVE-2009-3080 [HIGH] CWE-839 kernel: gdth: Prevent negative offsets in ioctl
kernel: gdth: Prevent negative offsets in ioctl
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
GHSA
GHSA-r6gw-jh8m-7g87: Array index error in the gdth_read_event function in drivers/scsi/gdth
ghsa_unreviewed·2022-05-02
CVE-2009-3080 [HIGH] CWE-129 GHSA-r6gw-jh8m-7g87: Array index error in the gdth_read_event function in drivers/scsi/gdth
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=690e744869f3262855b83b4fb59199cf142765b0http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.htmlhttp://secunia.com/advisories/37435http://secunia.com/advisories/37720http://secunia.com/advisories/37909http://secunia.com/advisories/38017http://secunia.com/advisories/38276http://support.avaya.com/css/P8/documents/100073666http://www.debian.org/security/2010/dsa-2005http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc8http://www.mandriva.com/security/advisories?name=MDVSA-2010:030http://www.mandriva.com/security/advisories?name=MDVSA-2011:051http://www.redhat.com/support/errata/RHSA-2010-0041.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0882.htmlhttp://www.securityfocus.com/bid/37068http://www.ubuntu.com/usn/usn-864-1http://www.vmware.com/security/advisories/VMSA-2011-0009.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10989https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12862https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7101https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00777.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=690e744869f3262855b83b4fb59199cf142765b0http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.htmlhttp://secunia.com/advisories/37435http://secunia.com/advisories/37720http://secunia.com/advisories/37909http://secunia.com/advisories/38017http://secunia.com/advisories/38276http://support.avaya.com/css/P8/documents/100073666http://www.debian.org/security/2010/dsa-2005http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc8http://www.mandriva.com/security/advisories?name=MDVSA-2010:030http://www.mandriva.com/security/advisories?name=MDVSA-2011:051http://www.redhat.com/support/errata/RHSA-2010-0041.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0882.htmlhttp://www.securityfocus.com/bid/37068http://www.ubuntu.com/usn/usn-864-1http://www.vmware.com/security/advisories/VMSA-2011-0009.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10989https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12862https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7101https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00777.html
2009-11-20
Published