First published: Wed Jan 28 2009(Updated: )
drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | <2.6.27.13 | |
Linux kernel | >=2.6.28<2.6.28.2 | |
Debian | =4.0 | |
Debian | =5.0 | |
Ubuntu Linux | =7.10 | |
Ubuntu Linux | =8.04 | |
Ubuntu Linux | =8.10 | |
Linux Kernel | <2.6.27.13 | |
Linux Kernel | >=2.6.28<2.6.28.2 | |
Ubuntu | =7.10 | |
Ubuntu | =8.04 | |
Ubuntu | =8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0322 is considered to have a medium severity as it can lead to a local denial of service by triggering a system crash.
To fix CVE-2009-0322, users should upgrade to a version of the Linux kernel that is newer than 2.6.27.13 or between 2.6.28.2 and later.
CVE-2009-0322 affects the Linux kernel versions prior to 2.6.27.13 and 2.6.28.x before 2.6.28.2, as well as specific Debian and Ubuntu Linux distributions.
CVE-2009-0322 allows local users to crash the system through a denial of service attack via specific read system calls.
No, CVE-2009-0322 is not a remote vulnerability as it requires local user access to exploit.