CVE-2009-3238
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via…
Does this matter?
Lower severity and a low EPSS score (1.63%). Track it; it rarely justifies an emergency change on its own.
Description
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-338
- Affected
- linux/linux kernel · canonical/ubuntu linux · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server
- Source
- cve@mitre.org
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8a0a9bd4db63bc45e3017bedeafbd88d0eb84d02Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlMailing List
- http://patchwork.kernel.org/patch/21766/Broken Link, Patch
- http://secunia.com/advisories/37105Broken Link
- http://secunia.com/advisories/37351Broken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30Broken Link, Exploit, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1438.htmlBroken Link
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=499785Issue Tracking, Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=519692Issue Tracking, Permissions Required
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11168Broken Link
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03836en_usThird Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8a0a9bd4db63bc45e3017bedeafbd88d0eb84d02Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlMailing List
- http://patchwork.kernel.org/patch/21766/Broken Link, Patch
- http://secunia.com/advisories/37105Broken Link
- http://secunia.com/advisories/37351Broken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30Broken Link, Exploit, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1438.htmlBroken Link
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=499785Issue Tracking, Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=519692Issue Tracking, Permissions Required
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11168Broken Link
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03836en_usThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.