CVE-2009-2903
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 3.85% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-772
- Affected
- linux/linux kernel · suse/linux enterprise debuginfo · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/davem/net-next-2.6.git%3Ba=commit%3Bh=ffcfb8db540ff879c2a85bf7e404954281443414
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/36707Third Party Advisory
- http://secunia.com/advisories/37105Third Party Advisory
- http://secunia.com/advisories/37909Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:329Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/14/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/14/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/17/11Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/36379Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=522331Issue Tracking, Third Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/davem/net-next-2.6.git%3Ba=commit%3Bh=ffcfb8db540ff879c2a85bf7e404954281443414
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/36707Third Party Advisory
- http://secunia.com/advisories/37105Third Party Advisory
- http://secunia.com/advisories/37909Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:329Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/14/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/14/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/17/11Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/36379Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=522331Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.