CVE-2009-4538
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 8.38% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/38031Third Party Advisory
- http://secunia.com/advisories/38276Third Party Advisory
- http://secunia.com/advisories/38296Third Party Advisory
- http://secunia.com/advisories/38492Third Party Advisory
- http://secunia.com/advisories/38610Third Party Advisory
- http://secunia.com/advisories/38779Third Party Advisory
- http://securitytracker.com/id?1023420Third Party Advisory, VDB Entry
- http://www.debian.org/security/2010/dsa-1996Third Party Advisory
- http://www.debian.org/security/2010/dsa-2005Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:066Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/12/28/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/12/29/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/12/31/1Mailing List, Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0019.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0020.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0041.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0053.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0111.htmlThird Party Advisory
- http://www.securityfocus.com/bid/37523Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=551214Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55645Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7016Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9702Third Party Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0095.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.