CVE-2009-1385

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ea30e11970a96cfe5e32c03a29332554573b4a10

http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html

http://osvdb.org/54892

http://secunia.com/advisories/35265

http://secunia.com/advisories/35566

http://secunia.com/advisories/35623

http://secunia.com/advisories/35656

http://secunia.com/advisories/35847

http://secunia.com/advisories/36051

http://secunia.com/advisories/36131

http://secunia.com/advisories/36327

http://secunia.com/advisories/37471

http://sourceforge.net/project/shownotes.php?release_id=504022&group_id=42302

http://wiki.rpath.com/Advisories:rPSA-2009-0111

http://www.debian.org/security/2009/dsa-1844

http://www.debian.org/security/2009/dsa-1865

http://www.intel.com/support/network/sb/CS-030543.htm

http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8

http://www.mandriva.com/security/advisories?name=MDVSA-2009:135

http://www.mandriva.com/security/advisories?name=MDVSA-2009:148

http://www.openwall.com/lists/oss-security/2009/06/03/2

http://www.redhat.com/support/errata/RHSA-2009-1157.html

http://www.redhat.com/support/errata/RHSA-2009-1193.html

http://www.securityfocus.com/archive/1/505254/100/0/threaded

http://www.securityfocus.com/archive/1/507985/100/0/threaded

http://www.securityfocus.com/archive/1/512019/100/0/threaded

http://www.securityfocus.com/bid/35185

http://www.ubuntu.com/usn/usn-793-1

http://www.vmware.com/security/advisories/VMSA-2009-0016.html

http://www.vupen.com/english/advisories/2009/3316

https://bugzilla.redhat.com/show_bug.cgi?id=502981

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11598

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11681

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8340

https://rhn.redhat.com/errata/RHSA-2009-1550.html

https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.html

https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.html

https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.html

Details

Source: MITRE

Published: 2009-06-04

Updated: 2018-10-10

Type: CWE-189

Risk Information

CVSS v2

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:intel:e1000:5.2.22:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.2.30.1:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.2.52:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.3.19:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.4.11:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.5.4:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.6.10:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.6.10.1:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:5.7.6:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:6.0.54:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:6.0.60:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:6.1.16:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:6.2.15:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:6.3.9:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.0.33:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.0.41:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.1.9:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.2.7:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.2.9:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.3.15:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.3.20:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:7.4.27:*:*:*:*:*:*:*

cpe:2.3:a:intel:e1000:*:*:*:*:*:*:*:* versions up to 7.4.35 (inclusive)

cpe:2.3:a:linux:kernel:2.6.24.7:*:*:*:*:*:*:*

cpe:2.3:a:linux:kernel:2.6.25.15:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.2.27:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.4.36:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.4.36.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.4.36.2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.4.36.3:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.4.36.4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.4.36.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.4.36.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:rc1:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:rc2:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:rc3:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:rc4:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:rc5:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:rc6:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.18:rc7:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.19.4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.19.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.19.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.19.7:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.20.16:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.20.17:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.20.18:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.20.19:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.20.20:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.20.21:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.21.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.21.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.21.7:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.8:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.9:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.10:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.11:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.12:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.13:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.14:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.15:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.17:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.18:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.19:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.20:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.21:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22.22:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22_rc1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.22_rc7:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.8:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.9:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.10:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.11:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.12:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.13:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.15:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.16:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23.17:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.23_rc1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24.2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24.3:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24.4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24_rc1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24_rc4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.24_rc5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.1:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.2:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.3:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.3:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.4:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.5:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.6:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.7:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.7:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.8:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.8:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.9:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.9:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.10:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.10:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.11:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.11:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.12:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.12:*:x86_64:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.13:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.14:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.16:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.17:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.3:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.27:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 2.6.28 (inclusive)

cpe:2.3:o:linux:linux_kernel:2.6.29:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29:git1:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29:rc1:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29:rc2:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29:rc2_git7:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29:rc8-kk:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29.3:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29.rc1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29.rc2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.29.rc2-git1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.30:rc1:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.30:rc2:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.30:rc3:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:*:rc7-git6:*:*:*:*:*:* versions up to 2.6.30 (inclusive)

Tenable Plugins

View all (29 total)

IDNameProductFamilySeverity
89117VMware ESX / ESXi Multiple Vulnerabilities (VMSA-2009-0016) (remote check)NessusMisc.
critical
67955Oracle Linux 3 : kernel (ELSA-2009-1550)NessusOracle Linux Local Security Checks
high
67904Oracle Linux 5 : kernel (ELSA-2009-1193)NessusOracle Linux Local Security Checks
high
67884Oracle Linux 4 : kernel (ELSA-2009-1132)NessusOracle Linux Local Security Checks
high
67070CentOS 3 : kernel (CESA-2009:1550)NessusCentOS Local Security Checks
high
63915RHEL 5 : kernel (RHSA-2010:0079)NessusRed Hat Local Security Checks
critical
60688Scientific Linux Security Update : kernel on SL3.x i386/x86_64NessusScientific Linux Local Security Checks
high
60634Scientific Linux Security Update : kernel for SL 5.x on i386/x86_64NessusScientific Linux Local Security Checks
high
60609Scientific Linux Security Update : kernel on SL4.x i386/x86_64NessusScientific Linux Local Security Checks
high
51607SuSE 11 Security Update : Linux kernel (SAT Patch Numbers 1079 / 1087)NessusSuSE Local Security Checks
high
48149Mandriva Linux Security Advisory : kernel (MDVSA-2009:148)NessusMandriva Local Security Checks
high
47150VMSA-2010-0010 : ESX 3.5 third-party update for Service Console kernelNessusVMware ESX Local Security Checks
high
44730Debian DSA-1865-1 : linux-2.6 - denial of service/privilege escalationNessusDebian Local Security Checks
high
44709Debian DSA-1844-1 : linux-2.6.24 - denial of service/privilege escalationNessusDebian Local Security Checks
high
43773CentOS 5 : kernel (CESA-2009:1193)NessusCentOS Local Security Checks
high
42870VMSA-2009-0016 : VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.NessusVMware ESX Local Security Checks
medium
42360RHEL 3 : kernel (RHSA-2009:1550)NessusRed Hat Local Security Checks
high
41413SuSE 11 Security Update : Linux kernel (SAT Patch Number 1086)NessusSuSE Local Security Checks
high
41412SuSE 11 Security Update : Linux kernel (SAT Patch Number 1086)NessusSuSE Local Security Checks
high
40783openSUSE Security Update : kernel (kernel-1211)NessusSuSE Local Security Checks
high
40487RHEL 5 : kernel (RHSA-2009:1193)NessusRed Hat Local Security Checks
high
40360openSUSE Security Update : kernel (kernel-1097)NessusSuSE Local Security Checks
high
39586Ubuntu 6.06 LTS / 8.04 LTS / 8.10 / 9.04 : linux, linux-source-2.6.15 vulnerabilities (USN-793-1)NessusUbuntu Local Security Checks
high
39583RHEL 4 : kernel (RHSA-2009:1132)NessusRed Hat Local Security Checks
high
39511Fedora 10 : kernel-2.6.27.25-170.2.72.fc10 (2009-6883)NessusFedora Local Security Checks
high
39510Fedora 9 : kernel-2.6.27.25-78.2.56.fc9 (2009-6846)NessusFedora Local Security Checks
high
39506Fedora 11 : kernel-2.6.29.5-191.fc11 (2009-6768)NessusFedora Local Security Checks
high
39444Mandriva Linux Security Advisory : kernel (MDVSA-2009:135)NessusMandriva Local Security Checks
high
801471CentOS RHSA-2009-1193 Security CheckLog Correlation EngineGeneric
high