CVE-2009-3612: Infoleak
Quote from http://patchwork.ozlabs.org/patch/35412/: Commit 9ef1d4c7c7aca1cd436612b6ca785b726ffb8ed8 introduced a typo in initialization.
Other sources
The tcffillnode function in net/sched/clsapi.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcmpad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3612?
CVE-2009-3612 is classified as a medium severity vulnerability due to its potential impact on the Linux kernel's netlink subsystem.
How do I fix CVE-2009-3612?
To fix CVE-2009-3612, you should update your Linux kernel to a version that is patched against this vulnerability.
Which Linux distributions are affected by CVE-2009-3612?
CVE-2009-3612 affects various distributions including certain versions of Red Hat, openSUSE, SUSE Linux Enterprise, and Ubuntu.
What does CVE-2009-3612 exploit?
CVE-2009-3612 exploits a typo in the initialization of the tcf_fill_node function within the netlink subsystem of the Linux kernel.
What versions of the Linux kernel are impacted by CVE-2009-3612?
CVE-2009-3612 impacts Linux kernel versions prior to 2.6.32 and certain 2.6.x versions including those specified in the advisory.