First published: Thu Sep 10 2009(Updated: )
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=2.4.0<=2.4.37.6 | |
Linux Kernel | >=2.6.0<=2.6.31 | |
SUSE Linux Enterprise Debuginfo | =10-sp2 | |
SUSE Linux Enterprise Debuginfo | =10-sp3 | |
SUSE Linux Enterprise Desktop with Beagle | =10-sp2 | |
SUSE Linux Enterprise Desktop with Beagle | =10-sp3 | |
SUSE Linux Enterprise Server | =9 | |
SUSE Linux Enterprise Server | =10-sp2 | |
SUSE Linux Enterprise Server | =10-sp3 | |
SUSE Linux Enterprise Software Development Kit | =10-sp2 | |
SUSE Linux Enterprise Software Development Kit | =10-sp3 | |
Ubuntu Linux | =6.06 | |
Ubuntu Linux | =8.04 | |
Ubuntu Linux | =8.10 | |
Ubuntu Linux | =9.04 | |
Ubuntu | =9.04 | |
Ubuntu | =8.10 | |
Ubuntu | =8.04 | |
Ubuntu | =6.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2903 is classified as a denial of service vulnerability due to a memory leak in the appletalk subsystem.
To fix CVE-2009-2903, update your Linux kernel to a version beyond 2.6.31 or 2.4.37.6.
CVE-2009-2903 affects Linux kernel versions 2.4.x up to 2.4.37.6 and 2.6.x up to 2.6.31.
Yes, CVE-2009-2903 can be exploited remotely via IP-DDP datagrams.
Exploiting CVE-2009-2903 can lead to denial of service due to increased memory consumption.