CVE-2009-3238
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."
Affected (8)
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.30 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.06 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 | |
| Version 10 sp2 | |
| Version 10 sp2 |
References (26)
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Broken LinkExploitVendor Advisory
Source: cve@mitre.org
Issue TrackingPermissions Required
Source: cve@mitre.org
Issue TrackingPermissions Required
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.