CVE-2009-2844: Null Pointer Dereference
cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmpies function. NOTE: a potential weakness in the ismesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2844?
CVE-2009-2844 has a severity rating that indicates it can cause a denial of service (DoS) leading to system crashes.
How do I fix CVE-2009-2844?
To address CVE-2009-2844, you should upgrade to Linux kernel versions 2.6.31-rc6 or later.
What systems are affected by CVE-2009-2844?
CVE-2009-2844 affects various versions of the Linux kernel prior to 2.6.31-rc6.
What type of vulnerability is CVE-2009-2844?
CVE-2009-2844 is classified as a denial of service vulnerability.
Can CVE-2009-2844 be exploited remotely?
Yes, CVE-2009-2844 can be exploited by remote attackers through crafted beacon frames.