CVE-2009-3612Sensitive Information Exposure in Kernel

Severity
2.1LOWNVD
CNA4.9
EPSS
0.1%
top 77.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateNov 21

Description

The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages5 packages

Also affects: Ubuntu Linux 6.06, 8.04, 8.10, 9.04, 9.10, Fedora 10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vr55-mp4p-wfh2: The tcf_fill_node function in net/sched/cls_api2022-05-02
CVEList
CVE-2009-3612: The tcf_fill_node function in net/sched/cls_api2009-10-19

📋Vendor Advisories

2
Ubuntu
Linux kernel vulnerabilities2009-12-05
Red Hat
kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c72009-10-08

📄Research Papers

2
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel2025-11-21
arXiv
Quantifying Information Leak Vulnerabilities2010-07-06

💬Community

1
Bugzilla
CVE-2009-3612 kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c72009-10-14
CVE-2009-3612 — Sensitive Information Exposure | cvebase