CVE-2009-3228: Low severity linux kernel vulnerability
Description of problem: Three bytes of uninitialized kernel memory are currently leaked to user.
Upstream proposed patch: http://patchwork.ozlabs.org/patch/32830/
CVE request: http://article.gmane.org/gmane.comp.security.oss.general/2060
Other sources
The tcfilltclass function in net/sched/schapi.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcmpad1 and (2) tcmpad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3228?
CVE-2009-3228 has a moderate severity level as it involves leakage of uninitialized kernel memory.
How do I fix CVE-2009-3228?
To fix CVE-2009-3228, apply the proposed patch available from the upstream source.
Which versions are affected by CVE-2009-3228?
CVE-2009-3228 affects specific versions of the Linux kernel including those from 2.4.0 up to 2.6.31.
What causes CVE-2009-3228?
CVE-2009-3228 is caused by uninitialized memory being inadvertently leaked to user space.
Is CVE-2009-3228 exploitable remotely?
CVE-2009-3228 does not pose a direct remote exploitation vector but may aid in local privilege escalation.