{"api_version":"1","generated_at":"2026-07-23T08:38:06+00:00","cve":"CVE-2009-1046","urls":{"html":"https://cve.report/CVE-2009-1046","api":"https://cve.report/api/cve/CVE-2009-1046.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1046","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1046"},"summary":{"title":"CVE-2009-1046","description":"The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an \"off-by-two memory error.\" NOTE: it is not clear whether this issue crosses privilege boundaries.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-03-23 16:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-399","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.7","severity":"","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:N/A:C","baseScore":4.7,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/34981","name":"http://secunia.com/advisories/34981","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian update for linux-2.6.24 - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/02/12/9","name":"http://www.openwall.com/lists/oss-security/2009/02/12/9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - http://www.securityfocus.com/bid/33672/info kernel issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2009/dsa-1787","name":"http://www.debian.org/security/2009/dsa-1787","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1787-1 linux-2.6.24","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.openwall.net/linux-kernel/2009/02/02/364","name":"http://lists.openwall.net/linux-kernel/2009/02/02/364","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"linux-kernel - Re: [PATCH] Fix memory corruption in console selection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4","name":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/34917","name":"http://secunia.com/advisories/34917","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat update for kernel-rt - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.openwall.net/linux-kernel/2009/01/30/333","name":"http://lists.openwall.net/linux-kernel/2009/01/30/333","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"linux-kernel - [PATCH] Fix memory corruption in console selection","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2009-0451.html","name":"http://www.redhat.com/support/errata/RHSA-2009-0451.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35121","name":"http://secunia.com/advisories/35121","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian update for linux-2.6 - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2009/dsa-1800","name":"http://www.debian.org/security/2009/dsa-1800","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1800-1 linux-2.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-751-1","name":"http://www.ubuntu.com/usn/usn-751-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-751-1: Linux kernel vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/02/12/11","name":"http://www.openwall.com/lists/oss-security/2009/02/12/11","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: http://www.securityfocus.com/bid/33672/info kernel issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33672","name":"http://www.securityfocus.com/bid/33672","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Linux Kernel Console Selection Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2009/02/12/10","name":"http://www.openwall.com/lists/oss-security/2009/02/12/10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: http://www.securityfocus.com/bid/33672/info kernel\n issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1046","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1046","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1046","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.25","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1046","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.28","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1046","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.28.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1046","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.28.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1046","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.28.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-1046","organization":"Red Hat","lastmodified":"2009-05-19","contributor":"Tomas Hoger","statementText":"This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5. It was addressed in Red Hat Enterprise MRG via: https://rhn.redhat.com/errata/RHSA-2009-0451.html .","cve_year":"2009","cve_id":"1046","crc32":"53044850"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:57:17.563Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4"},{"name":"[oss-security] 20090212 http://www.securityfocus.com/bid/33672/info kernel issue","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/9"},{"name":"[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/10"},{"name":"33672","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33672"},{"name":"USN-751-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-751-1"},{"name":"[linux-kernel] 20090202 Re: [PATCH] Fix memory corruption in console selection","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.openwall.net/linux-kernel/2009/02/02/364"},{"name":"34981","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34981"},{"name":"DSA-1800","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1800"},{"name":"[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel issue","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/11"},{"name":"34917","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34917"},{"name":"DSA-1787","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1787"},{"name":"RHSA-2009:0451","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2009-0451.html"},{"name":"[linux-kernel] 20090130 [PATCH] Fix memory corruption in console selection","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.openwall.net/linux-kernel/2009/01/30/333"},{"name":"35121","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35121"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-02-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an \"off-by-two memory error.\" NOTE: it is not clear whether this issue crosses privilege boundaries."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-04-04T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4"},{"name":"[oss-security] 20090212 http://www.securityfocus.com/bid/33672/info kernel issue","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/9"},{"name":"[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/10"},{"name":"33672","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33672"},{"name":"USN-751-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-751-1"},{"name":"[linux-kernel] 20090202 Re: [PATCH] Fix memory corruption in console selection","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.openwall.net/linux-kernel/2009/02/02/364"},{"name":"34981","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34981"},{"name":"DSA-1800","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1800"},{"name":"[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel issue","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/11"},{"name":"34917","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34917"},{"name":"DSA-1787","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1787"},{"name":"RHSA-2009:0451","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2009-0451.html"},{"name":"[linux-kernel] 20090130 [PATCH] Fix memory corruption in console selection","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.openwall.net/linux-kernel/2009/01/30/333"},{"name":"35121","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35121"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1046","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an \"off-by-two memory error.\" NOTE: it is not clear whether this issue crosses privilege boundaries."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4"},{"name":"[oss-security] 20090212 http://www.securityfocus.com/bid/33672/info kernel issue","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/02/12/9"},{"name":"[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/02/12/10"},{"name":"33672","refsource":"BID","url":"http://www.securityfocus.com/bid/33672"},{"name":"USN-751-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-751-1"},{"name":"[linux-kernel] 20090202 Re: [PATCH] Fix memory corruption in console selection","refsource":"MLIST","url":"http://lists.openwall.net/linux-kernel/2009/02/02/364"},{"name":"34981","refsource":"SECUNIA","url":"http://secunia.com/advisories/34981"},{"name":"DSA-1800","refsource":"DEBIAN","url":"http://www.debian.org/security/2009/dsa-1800"},{"name":"[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel issue","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/02/12/11"},{"name":"34917","refsource":"SECUNIA","url":"http://secunia.com/advisories/34917"},{"name":"DSA-1787","refsource":"DEBIAN","url":"http://www.debian.org/security/2009/dsa-1787"},{"name":"RHSA-2009:0451","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2009-0451.html"},{"name":"[linux-kernel] 20090130 [PATCH] Fix memory corruption in console selection","refsource":"MLIST","url":"http://lists.openwall.net/linux-kernel/2009/01/30/333"},{"name":"35121","refsource":"SECUNIA","url":"http://secunia.com/advisories/35121"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1046","datePublished":"2009-03-23T16:00:00.000Z","dateReserved":"2009-03-23T00:00:00.000Z","dateUpdated":"2024-08-07T04:57:17.563Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-03-23 16:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-399","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:N/A:C","baseScore":4.7,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.25:*:*:*:*:*:*:*","matchCriteriaId":"71295664-89EC-4BB3-9F86-B1DDA20FAC5A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.28:*:*:*:*:*:*:*","matchCriteriaId":"26BD805F-08EB-42EC-BC54-26A7278E5089"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.28.1:*:*:*:*:*:*:*","matchCriteriaId":"217715A5-E69D-45C0-B8E4-5681528C651B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.28.2:*:*:*:*:*:*:*","matchCriteriaId":"A87AD66C-4321-4459-8556-3B0BA38C493A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.28.3:*:*:*:*:*:*:*","matchCriteriaId":"87A347E0-9C0B-4674-9363-3C36DA27AC45"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1046","Ordinal":"1","Title":"CVE-2009-1046","CVE":"CVE-2009-1046","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1046","Ordinal":"1","NoteData":"The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an \"off-by-two memory error.\" NOTE: it is not clear whether this issue crosses privilege boundaries.","Type":"Description","Title":"CVE-2009-1046"},{"CveYear":"2009","CveId":"1046","Ordinal":"2","NoteData":"2009-03-23","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1046","Ordinal":"3","NoteData":"2016-04-04","Type":"Other","Title":"Modified"}]}}}