CVE-2009-1385
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 33.49% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- intel/e1000 · linux/kernel · linux/linux kernel
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ea30e11970a96cfe5e32c03a29332554573b4a10
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html
- http://osvdb.org/54892
- http://secunia.com/advisories/35265Vendor Advisory
- http://secunia.com/advisories/35566
- http://secunia.com/advisories/35623
- http://secunia.com/advisories/35656
- http://secunia.com/advisories/35847
- http://secunia.com/advisories/36051
- http://secunia.com/advisories/36131
- http://secunia.com/advisories/36327
- http://secunia.com/advisories/37471
- http://sourceforge.net/project/shownotes.php?release_id=504022&group_id=42302Patch
- http://wiki.rpath.com/Advisories:rPSA-2009-0111
- http://www.debian.org/security/2009/dsa-1844
- http://www.debian.org/security/2009/dsa-1865
- http://www.intel.com/support/network/sb/CS-030543.htm
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:135
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:148
- http://www.openwall.com/lists/oss-security/2009/06/03/2
- http://www.redhat.com/support/errata/RHSA-2009-1157.html
- http://www.redhat.com/support/errata/RHSA-2009-1193.html
- http://www.securityfocus.com/archive/1/505254/100/0/threaded
- http://www.securityfocus.com/archive/1/507985/100/0/threaded
- http://www.securityfocus.com/archive/1/512019/100/0/threaded
- http://www.securityfocus.com/bid/35185
- http://www.ubuntu.com/usn/usn-793-1
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html
- http://www.vupen.com/english/advisories/2009/3316
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.