Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 273912 (CVE-2009-1385)

Summary: Kernel: <2.6.30-rc8 e1000_clean_rx_irq DOS (CVE-2009-1385)
Product: Gentoo Security Reporter: Stefan Behte (RETIRED) <craig>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: hardened-kernel+disabled, kernel
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ea30e11970a96cfe5e32c03a29332554573b4a10
Whiteboard: [linux <2.6.27.25] [linux >=2.6.28 <2.6.29.5] [gp < 2.6.29-8]
Package list:
Runtime testing required: ---

Description Stefan Behte (RETIRED) gentoo-dev Security 2009-06-12 20:36:51 UTC
CVE-2009-1385 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1385):
  Integer underflow in the e1000_clean_rx_irq function in
  drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux
  kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and
  Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers
  to cause a denial of service (panic) via a crafted frame size.