CVE-2009-3080

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
References
Link Resource
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=690e744869f3262855b83b4fb59199cf142765b0
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html Mailing List Third Party Advisory
http://secunia.com/advisories/37435 Broken Link
http://secunia.com/advisories/37720 Broken Link
http://secunia.com/advisories/37909 Broken Link
http://secunia.com/advisories/38017 Broken Link
http://secunia.com/advisories/38276 Broken Link
http://support.avaya.com/css/P8/documents/100073666 Third Party Advisory
http://www.debian.org/security/2010/dsa-2005 Third Party Advisory
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc8 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2010:030 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2011:051 Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0041.html Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0882.html Broken Link
http://www.securityfocus.com/bid/37068 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-864-1 Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2011-0009.html Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10989 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12862 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7101 Third Party Advisory
https://rhn.redhat.com/errata/RHSA-2010-0046.html Third Party Advisory
https://rhn.redhat.com/errata/RHSA-2010-0095.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00777.html Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.32:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.32:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.32:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.32:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.32:rc5:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:-:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:o:vmware:esx:3.5:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:a:redhat:virtualization:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:5.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_workstation:5.0:*:*:*:*:*:*:*

Configuration 7 (hide)

cpe:2.3:o:redhat:fedora:10:*:*:*:*:*:*:*

History

13 Feb 2023, 02:20

Type Values Removed Values Added
Summary CVE-2009-3080 kernel: gdth: Prevent negative offsets in ioctl Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2009-3080', 'name': 'https://access.redhat.com/security/cve/CVE-2009-3080', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0882', 'name': 'https://access.redhat.com/errata/RHSA-2010:0882', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0076', 'name': 'https://access.redhat.com/errata/RHSA-2010:0076', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=539414', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=539414', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0046', 'name': 'https://access.redhat.com/errata/RHSA-2010:0046', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0041', 'name': 'https://access.redhat.com/errata/RHSA-2010:0041', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 14:15

Type Values Removed Values Added
Summary Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request. CVE-2009-3080 kernel: gdth: Prevent negative offsets in ioctl
References
  • {'url': 'http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=690e744869f3262855b83b4fb59199cf142765b0', 'name': 'http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=690e744869f3262855b83b4fb59199cf142765b0', 'tags': ['Mailing List', 'Patch', 'Vendor Advisory'], 'refsource': 'CONFIRM'}
  • (MISC) https://access.redhat.com/security/cve/CVE-2009-3080 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0882 -
  • (MISC) http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=690e744869f3262855b83b4fb59199cf142765b0 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0076 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=539414 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0046 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0041 -

Information

Published : 2009-11-20 17:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-3080

Mitre link : CVE-2009-3080

CVE.ORG link : CVE-2009-3080


JSON object : View

Products Affected

suse

  • linux_enterprise_server
  • linux_enterprise_desktop

linux

  • linux_kernel

opensuse

  • opensuse

redhat

  • enterprise_linux_server
  • enterprise_linux_server_workstation
  • enterprise_linux_desktop
  • enterprise_linux_eus
  • fedora
  • virtualization

vmware

  • esx

canonical

  • ubuntu_linux

debian

  • debian_linux
CWE
CWE-129

Improper Validation of Array Index