CVE-2009-3612
published 2009-10-19CVE-2009-3612: The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.40%
32.2th percentile
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | <= 2.4.37.6 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.0 < 2.6.32 | 2.6.32 |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-12-05·CVSS 4.9
CVE-2009-3726 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the AX.25 network subsystem did not correctly
check integer signedness in certain setsockopt calls. A local attacker
could exploit this to crash the system, leading to a denial of service.
Ubuntu 9.10 was not affected. (CVE-2009-2909)
Jan Beulich discovered that the kernel could leak register contents to
32-bit processes that were switched to 64-bit mode. A local attacker
could run a specially crafted binary to read register values from an
earlier process, leading to a loss of privacy. (CVE-2009-2910)
Dave Jones discovered that the gdth SCSI driver did not correctly validate
array indexes in certain ioctl calls. A local attacker could exploit
this to crash the system or gain elevated privil
Red Hat
kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
vendor_redhat·2009-10-08·CVSS 4.9
CVE-2009-3612 [MEDIUM] kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
Statement: This issue is not planned to be fixed in Red Hat Enterprise Linux 3 due to this product being in Production 3 of its maintenance life-cycle, where only qualified security errata of important or critical impact are addressed.
For further information about the Errata Support Policy, visit: https://access.redhat.com/support/policy/updates/errata/
GHSA
GHSA-vr55-mp4p-wfh2: The tcf_fill_node function in net/sched/cls_api
ghsa_unreviewed·2022-05-02·CVSS 4.9
CVE-2009-3612 [MEDIUM] CWE-200 GHSA-vr55-mp4p-wfh2: The tcf_fill_node function in net/sched/cls_api
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
No detection rules found.
No public exploits indexed.
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
arXiv
Quantifying Information Leak Vulnerabilities
arxiv_fulltext·2010-07-06
Quantifying Information Leak Vulnerabilities
Quantifying Information Leak Vulnerabilities
Jonathan Heusser^
Pasquale Malacaria^
6 July 2010, [email protected] [email protected]
## Abstract
Leakage of confidential information represents a serious security risk.
Despite a number of novel, theoretical advances, it has been unclear if and how quantitative approaches to measuring leakage of confidential information could be applied to substantial, real-world programs. This is mostly due to the high complexity of computing precise leakage quantities.
In this paper, we introduce a technique which makes it possible to decide if a program conforms to a quantitative policy which scales to large state-spaces with the help of bounded model checking.
Our technique is applied to a number of officially reported information leak v
Bugzilla
CVE-2009-3612 kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
bugzilla·2009-10-14·CVSS 4.9
CVE-2009-3612 [MEDIUM] CVE-2009-3612 kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
CVE-2009-3612 kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
Quote from http://patchwork.ozlabs.org/patch/35412/:
Commit 9ef1d4c7c7aca1cd436612b6ca785b726ffb8ed8 introduced a typo in initialization.
Discussion:
Incomplete fix for CVE-2005-4881.
---
Official upstream patch, now in 2.6.32-rc5:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff_plain;h=ad61df918c44316940404891d5082c63e79c256a
---
kernel-2.6.30.9-90.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/kernel-2.6.30.9-90.fc11
---
MITRE's CVE-2009-3612 record:
The tcf_fill_node function in net/sched/cls_api.c in the netlink
subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6
and earlier, does not initialize a certain tcm__pad2 str
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ad61df918c44316940404891d5082c63e79c256ahttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://patchwork.ozlabs.org/patch/35412/http://secunia.com/advisories/37086http://secunia.com/advisories/37909http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc5http://www.mandriva.com/security/advisories?name=MDVSA-2009:329http://www.openwall.com/lists/oss-security/2009/10/14/1http://www.openwall.com/lists/oss-security/2009/10/14/2http://www.openwall.com/lists/oss-security/2009/10/15/1http://www.openwall.com/lists/oss-security/2009/10/15/3http://www.redhat.com/support/errata/RHSA-2009-1670.htmlhttp://www.ubuntu.com/usn/usn-864-1http://www.vupen.com/english/advisories/2010/0528https://bugzilla.redhat.com/show_bug.cgi?id=528868https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10395https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7557https://rhn.redhat.com/errata/RHSA-2009-1540.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00190.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ad61df918c44316940404891d5082c63e79c256ahttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://patchwork.ozlabs.org/patch/35412/http://secunia.com/advisories/37086http://secunia.com/advisories/37909http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc5http://www.mandriva.com/security/advisories?name=MDVSA-2009:329http://www.openwall.com/lists/oss-security/2009/10/14/1http://www.openwall.com/lists/oss-security/2009/10/14/2http://www.openwall.com/lists/oss-security/2009/10/15/1http://www.openwall.com/lists/oss-security/2009/10/15/3http://www.redhat.com/support/errata/RHSA-2009-1670.htmlhttp://www.ubuntu.com/usn/usn-864-1http://www.vupen.com/english/advisories/2010/0528https://bugzilla.redhat.com/show_bug.cgi?id=528868https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10395https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7557https://rhn.redhat.com/errata/RHSA-2009-1540.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00190.html
2009-10-19
Published