SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0535

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory.

LOW 2.1EPSS 0.47%

Does this matter?

Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.

Description

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Affected
mandrakesoft/mandrake multi network firewall · suse/suse email server · suse/suse linux admin-cd for firewall · suse/suse linux connectivity server · suse/suse linux database server · suse/suse linux firewall cd · suse/suse linux firewall live-cd · suse/suse linux office server · suse/suse office server · conectiva/linux · engardelinux/secure community · engardelinux/secure linux · gentoo/linux · linux/linux kernel · mandrakesoft/mandrake linux · mandrakesoft/mandrake linux corporate server · suse/suse linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.