CVE-2009-3228

Publication date 19 October 2009

Last updated 24 July 2024


Ubuntu priority

The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.

Status

Package Ubuntu Release Status
linux 9.10 karmic
Not affected
9.04 jaunty
Fixed 2.6.28-17.58
8.10 intrepid
Fixed 2.6.27-16.44
8.04 LTS hardy
Fixed 2.6.24-26.64
6.06 LTS dapper Not in release
linux-source-2.6.15 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper
Fixed 2.6.15-55.81

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
linux

References

Related Ubuntu Security Notices (USN)

    • USN-864-1
    • Linux kernel vulnerabilities
    • 5 December 2009

Other references