CVE-2009-4537
published 2010-01-12CVE-2009-4537: drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
5.89%
92.5th percentile
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | <= 2.6.32.3 | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.8HIGH
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel regression
vendor_ubuntu·2010-06-04·CVSS 4.7
CVE-2010-0419 [MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: KVM regressed under some conditions in the Linux kernel.
USN-947-1 fixed vulnerabilities in the Linux kernel. Fixes for
CVE-2010-0419 caused failures when using KVM in certain situations.
This update reverts that fix until a better solution can be found.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Linux kernel did not correctly handle memory
protection of the Virtual Dynamic Shared Object page when running
a 32-bit application on a 64-bit kernel. A local attacker could
exploit this to cause a denial of service. (Only affected Ubuntu 6.06
LTS.) (CVE-2009-4271)
It was discovered that the r8169 network driver did not correctly check
the size of Ethernet frames. A remote attacker could send specially
cr
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2010-06-03·CVSS 4.7
CVE-2009-4271 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple flaws in the Linux kernel.
It was discovered that the Linux kernel did not correctly handle memory
protection of the Virtual Dynamic Shared Object page when running
a 32-bit application on a 64-bit kernel. A local attacker could
exploit this to cause a denial of service. (Only affected Ubuntu 6.06
LTS.) (CVE-2009-4271)
It was discovered that the r8169 network driver did not correctly check
the size of Ethernet frames. A remote attacker could send specially
crafted traffic to crash the system, leading to a denial of service.
(CVE-2009-4537)
Wei Yongjun discovered that SCTP did not correctly validate certain
chunks. A remote attacker could send specially crafted traffic to
monopolize CPU resources, leading to a denial of service. (Onl
Red Hat
kernel: e1000e frame fragment issue
vendor_redhat·2009-12-28·CVSS 7.8
CVE-2009-4538 [HIGH] kernel: e1000e frame fragment issue
kernel: e1000e frame fragment issue
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.
Red Hat
kernel: r8169 issue reported at 26c3
vendor_redhat·2009-12-28·CVSS 7.8
CVE-2009-4537 [HIGH] CWE-682 kernel: r8169 issue reported at 26c3
kernel: r8169 issue reported at 26c3
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
GHSA
GHSA-pvpv-c389-c5f8: drivers/net/r8169
ghsa_unreviewed·2022-05-02·CVSS 7.8
CVE-2009-4537 [HIGH] CWE-20 GHSA-pvpv-c389-c5f8: drivers/net/r8169
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
GHSA
GHSA-pm3r-x334-2847: drivers/net/e1000e/netdev
ghsa_unreviewed·2022-05-02·CVSS 7.8
CVE-2009-4538 [HIGH] GHSA-pm3r-x334-2847: drivers/net/e1000e/netdev
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.
No detection rules found.
No public exploits indexed.
http://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.htmlhttp://marc.info/?l=linux-netdev&m=126202972828626&w=2http://marc.info/?t=126202986900002&r=1&w=2http://secunia.com/advisories/38031http://secunia.com/advisories/38610http://secunia.com/advisories/39742http://secunia.com/advisories/39830http://secunia.com/advisories/40645http://securitytracker.com/id?1023419http://twitter.com/dakami/statuses/7104238406http://www.debian.org/security/2010/dsa-2053http://www.novell.com/linux/security/advisories/2010_23_kernel.htmlhttp://www.openwall.com/lists/oss-security/2009/12/28/1http://www.openwall.com/lists/oss-security/2009/12/29/2http://www.openwall.com/lists/oss-security/2009/12/31/1http://www.redhat.com/support/errata/RHSA-2010-0019.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0020.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0041.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0053.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0111.htmlhttp://www.securityfocus.com/bid/37521http://www.vupen.com/english/advisories/2010/1857https://bugzilla.redhat.com/show_bug.cgi?id=550907https://exchange.xforce.ibmcloud.com/vulnerabilities/55647https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7443https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9439https://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttp://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.htmlhttp://marc.info/?l=linux-netdev&m=126202972828626&w=2http://marc.info/?t=126202986900002&r=1&w=2http://secunia.com/advisories/38031http://secunia.com/advisories/38610http://secunia.com/advisories/39742http://secunia.com/advisories/39830http://secunia.com/advisories/40645http://securitytracker.com/id?1023419http://twitter.com/dakami/statuses/7104238406http://www.debian.org/security/2010/dsa-2053http://www.novell.com/linux/security/advisories/2010_23_kernel.htmlhttp://www.openwall.com/lists/oss-security/2009/12/28/1http://www.openwall.com/lists/oss-security/2009/12/29/2http://www.openwall.com/lists/oss-security/2009/12/31/1http://www.redhat.com/support/errata/RHSA-2010-0019.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0020.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0041.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0053.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0111.htmlhttp://www.securityfocus.com/bid/37521http://www.vupen.com/english/advisories/2010/1857https://bugzilla.redhat.com/show_bug.cgi?id=550907https://exchange.xforce.ibmcloud.com/vulnerabilities/55647https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7443https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9439https://rhn.redhat.com/errata/RHSA-2010-0095.html
2010-01-12
Published