CVE-2009-1385
high · 7.8Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
7.8
CVSS
33.7%
EPSS (exploit prob.)
98th
EPSS percentile
2009-06-04
Published
AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
CWE-189
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| intel | e1000 | <= 7.4.35 |
| intel | e1000 | 5.2.22 |
| intel | e1000 | 5.2.30.1 |
| intel | e1000 | 5.2.52 |
| intel | e1000 | 5.3.19 |
| intel | e1000 | 5.4.11 |
| intel | e1000 | 5.5.4 |
| intel | e1000 | 5.6.10 |
| intel | e1000 | 5.6.10.1 |
| intel | e1000 | 5.7.6 |
| intel | e1000 | 6.0.54 |
| intel | e1000 | 6.0.60 |
| intel | e1000 | 6.1.16 |
| intel | e1000 | 6.2.15 |
| intel | e1000 | 6.3.9 |
| intel | e1000 | 7.0.33 |
| intel | e1000 | 7.0.41 |
| intel | e1000 | 7.1.9 |
| intel | e1000 | 7.2.7 |
| intel | e1000 | 7.2.9 |
| intel | e1000 | 7.3.15 |
| intel | e1000 | 7.3.20 |
| intel | e1000 | 7.4.27 |
| linux | kernel | 2.6.24.7 |
| linux | kernel | 2.6.25.15 |
| linux | linux_kernel | <= 2.6.28 |
| linux | linux_kernel | <= 2.6.30 |
| linux | linux_kernel | 2.2.27 |
| linux | linux_kernel | 2.4.36 |
| linux | linux_kernel | 2.4.36.1 |
| linux | linux_kernel | 2.4.36.2 |
| linux | linux_kernel | 2.4.36.3 |
| linux | linux_kernel | 2.4.36.4 |
| linux | linux_kernel | 2.4.36.5 |
| linux | linux_kernel | 2.4.36.6 |
| linux | linux_kernel | 2.6 |
| linux | linux_kernel | 2.6.18 |
| linux | linux_kernel | 2.6.18 |
| linux | linux_kernel | 2.6.18 |
| linux | linux_kernel | 2.6.18 |
Check a specific version with /api/v1/cve/match.
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ea30e11970a96cfe5e32c03a29332554573b4a10
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html
- http://osvdb.org/54892
- http://secunia.com/advisories/35265
- http://secunia.com/advisories/35566
- http://secunia.com/advisories/35623
- http://secunia.com/advisories/35656
- http://secunia.com/advisories/35847
- http://secunia.com/advisories/36051
- http://secunia.com/advisories/36131
- http://secunia.com/advisories/36327
- http://secunia.com/advisories/37471
- http://sourceforge.net/project/shownotes.php?release_id=504022&group_id=42302
- http://wiki.rpath.com/Advisories:rPSA-2009-0111
- http://www.debian.org/security/2009/dsa-1844
- http://www.debian.org/security/2009/dsa-1865
- http://www.intel.com/support/network/sb/CS-030543.htm
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:135
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:148
- http://www.openwall.com/lists/oss-security/2009/06/03/2
- http://www.redhat.com/support/errata/RHSA-2009-1157.html
- http://www.redhat.com/support/errata/RHSA-2009-1193.html
- http://www.securityfocus.com/archive/1/505254/100/0/threaded
- http://www.securityfocus.com/archive/1/507985/100/0/threaded
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-1385