CVE-2009-2903

Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
References
Link Resource
http://git.kernel.org/?p=linux/kernel/git/davem/net-next-2.6.git%3Ba=commit%3Bh=ffcfb8db540ff879c2a85bf7e404954281443414
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html Mailing List Third Party Advisory
http://secunia.com/advisories/36707 Third Party Advisory
http://secunia.com/advisories/37105 Third Party Advisory
http://secunia.com/advisories/37909 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:329 Third Party Advisory
http://www.openwall.com/lists/oss-security/2009/09/14/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2009/09/14/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2009/09/17/11 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/36379 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-852-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=522331 Issue Tracking Third Party Advisory
http://git.kernel.org/?p=linux/kernel/git/davem/net-next-2.6.git%3Ba=commit%3Bh=ffcfb8db540ff879c2a85bf7e404954281443414
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html Mailing List Third Party Advisory
http://secunia.com/advisories/36707 Third Party Advisory
http://secunia.com/advisories/37105 Third Party Advisory
http://secunia.com/advisories/37909 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:329 Third Party Advisory
http://www.openwall.com/lists/oss-security/2009/09/14/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2009/09/14/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2009/09/17/11 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/36379 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-852-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=522331 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:suse:linux_enterprise_debuginfo:10:sp2:*:*:*:*:*:*
cpe:2.3:a:suse:linux_enterprise_debuginfo:10:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp3:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-09-15 22:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-2903

Mitre link : CVE-2009-2903

CVE.ORG link : CVE-2009-2903


JSON object : View

Products Affected

suse

  • linux_enterprise_desktop
  • linux_enterprise_server
  • linux_enterprise_software_development_kit
  • linux_enterprise_debuginfo

linux

  • linux_kernel

canonical

  • ubuntu_linux
CWE
CWE-772

Missing Release of Resource after Effective Lifetime