CVE-2009-1046
Summary
| CVE | CVE-2009-1046 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-23 16:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:L/AC:M/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.25 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.28.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian update for linux-2.6.24 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - http://www.securityfocus.com/bid/33672/info kernel issue | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Debian -- Security Information -- DSA-1787-1 linux-2.6.24 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| linux-kernel - Re: [PATCH] Fix memory corruption in console selection | af854a3a-2127-422b-91ae-364da2661108 | lists.openwall.net | Patch |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | |
| Red Hat update for kernel-rt - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| linux-kernel - [PATCH] Fix memory corruption in console selection | af854a3a-2127-422b-91ae-364da2661108 | lists.openwall.net | Patch |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for linux-2.6 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1800-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| USN-751-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| oss-security - Re: http://www.securityfocus.com/bid/33672/info kernel issue | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Linux Kernel Console Selection Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| oss-security - Re: http://www.securityfocus.com/bid/33672/info kernel issue | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-05-19 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5. It was addressed in Red Hat Enterprise MRG via: https://rhn.redhat.com/errata/RHSA-2009-0451.html . |
There are currently no legacy QID mappings associated with this CVE.