{"api_version":"1","generated_at":"2026-07-23T09:43:05+00:00","cve":"CVE-2009-4538","urls":{"html":"https://cve.report/CVE-2009-4538","api":"https://cve.report/api/cve/CVE-2009-4538.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-4538","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-4538"},"summary":{"title":"CVE-2009-4538","description":"drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-01-12 17:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/38296","name":"http://secunia.com/advisories/38296","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"SUSE update for kernel - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/12/29/2","name":"http://www.openwall.com/lists/oss-security/2009/12/29/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests - kernel security regressions for\n CVE-2009-1385/and -1389","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2010/dsa-2005","name":"http://www.debian.org/security/2010/dsa-2005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-2005-1 linux-2.6.24","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9702","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9702","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0053.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0053.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55645","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55645","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=551214","name":"https://bugzilla.redhat.com/show_bug.cgi?id=551214","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug 551214 – CVE-2009-4538 kernel: e1000e frame fragment issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0111.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0111.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7016","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7016","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38276","name":"http://secunia.com/advisories/38276","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"SUSE update for kernel - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2010/dsa-1996","name":"http://www.debian.org/security/2010/dsa-1996","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1996-1 linux-2.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0041.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0041.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:066","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:066","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2010:066 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/12/31/1","name":"http://www.openwall.com/lists/oss-security/2009/12/31/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests - kernel security regressions for\n CVE-2009-1385/and -1389","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38492","name":"http://secunia.com/advisories/38492","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for linux-2.6 - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/37523","name":"http://www.securityfocus.com/bid/37523","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linux e1000e Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/38779","name":"http://secunia.com/advisories/38779","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"SUSE update for kernel - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2010-0095.html","name":"https://rhn.redhat.com/errata/RHSA-2010-0095.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 12 Update: kernel-2.6.31.12-174.2.19.fc12","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38610","name":"http://secunia.com/advisories/38610","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for kernel - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1023420","name":"http://securitytracker.com/id?1023420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Linux Kernel Input Validation Flaw in Intel PRO/1000 Linux Drivers Lets Remote Users Deny Service and Potentially Bypass Security Controls","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0020.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0020.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38031","name":"http://secunia.com/advisories/38031","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for the kernel - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0019.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0019.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/12/28/1","name":"http://www.openwall.com/lists/oss-security/2009/12/28/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE requests - kernel security regressions for CVE-2009-1385/and\n -1389","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-4538","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4538","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"4538","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4538","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4538","vulnerable":"1","versionEndIncluding":"2.6.32.3","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:08:38.032Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38276","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38276"},{"name":"1023420","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023420"},{"name":"SUSE-SA:2010:007","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html"},{"name":"kernel-edriver-unspecified(55645)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55645"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=551214"},{"name":"RHSA-2010:0111","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0111.html"},{"name":"38779","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38779"},{"name":"38296","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38296"},{"name":"SUSE-SA:2010:012","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html"},{"name":"RHSA-2010:0053","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0053.html"},{"name":"SUSE-SA:2010:014","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html"},{"name":"DSA-1996","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2010/dsa-1996"},{"name":"RHSA-2010:0019","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0019.html"},{"name":"[oss-security] 20091228 CVE requests - kernel security regressions for CVE-2009-1385/and -1389","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/12/28/1"},{"name":"FEDORA-2010-1787","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html"},{"name":"MDVSA-2010:066","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:066"},{"name":"[oss-security] 20091229 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/12/29/2"},{"name":"RHSA-2010:0095","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0095.html"},{"name":"SUSE-SA:2010:005","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html"},{"name":"[oss-security] 20091231 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/12/31/1"},{"name":"oval:org.mitre.oval:def:9702","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9702"},{"name":"RHSA-2010:0020","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0020.html"},{"name":"38031","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38031"},{"name":"37523","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/37523"},{"name":"38610","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38610"},{"name":"oval:org.mitre.oval:def:7016","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7016"},{"name":"DSA-2005","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2010/dsa-2005"},{"name":"SUSE-SA:2010:010","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html"},{"name":"RHSA-2010:0041","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0041.html"},{"name":"38492","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38492"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-12-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"38276","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38276"},{"name":"1023420","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023420"},{"name":"SUSE-SA:2010:007","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html"},{"name":"kernel-edriver-unspecified(55645)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55645"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=551214"},{"name":"RHSA-2010:0111","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0111.html"},{"name":"38779","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38779"},{"name":"38296","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38296"},{"name":"SUSE-SA:2010:012","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html"},{"name":"RHSA-2010:0053","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0053.html"},{"name":"SUSE-SA:2010:014","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html"},{"name":"DSA-1996","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2010/dsa-1996"},{"name":"RHSA-2010:0019","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0019.html"},{"name":"[oss-security] 20091228 CVE requests - kernel security regressions for CVE-2009-1385/and -1389","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/12/28/1"},{"name":"FEDORA-2010-1787","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html"},{"name":"MDVSA-2010:066","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:066"},{"name":"[oss-security] 20091229 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/12/29/2"},{"name":"RHSA-2010:0095","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0095.html"},{"name":"SUSE-SA:2010:005","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html"},{"name":"[oss-security] 20091231 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/12/31/1"},{"name":"oval:org.mitre.oval:def:9702","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9702"},{"name":"RHSA-2010:0020","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0020.html"},{"name":"38031","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38031"},{"name":"37523","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/37523"},{"name":"38610","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38610"},{"name":"oval:org.mitre.oval:def:7016","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7016"},{"name":"DSA-2005","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2010/dsa-2005"},{"name":"SUSE-SA:2010:010","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html"},{"name":"RHSA-2010:0041","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0041.html"},{"name":"38492","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38492"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-4538","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38276","refsource":"SECUNIA","url":"http://secunia.com/advisories/38276"},{"name":"1023420","refsource":"SECTRACK","url":"http://securitytracker.com/id?1023420"},{"name":"SUSE-SA:2010:007","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html"},{"name":"kernel-edriver-unspecified(55645)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55645"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=551214","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=551214"},{"name":"RHSA-2010:0111","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0111.html"},{"name":"38779","refsource":"SECUNIA","url":"http://secunia.com/advisories/38779"},{"name":"38296","refsource":"SECUNIA","url":"http://secunia.com/advisories/38296"},{"name":"SUSE-SA:2010:012","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html"},{"name":"RHSA-2010:0053","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0053.html"},{"name":"SUSE-SA:2010:014","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html"},{"name":"DSA-1996","refsource":"DEBIAN","url":"http://www.debian.org/security/2010/dsa-1996"},{"name":"RHSA-2010:0019","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0019.html"},{"name":"[oss-security] 20091228 CVE requests - kernel security regressions for CVE-2009-1385/and -1389","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/12/28/1"},{"name":"FEDORA-2010-1787","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html"},{"name":"MDVSA-2010:066","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:066"},{"name":"[oss-security] 20091229 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/12/29/2"},{"name":"RHSA-2010:0095","refsource":"REDHAT","url":"https://rhn.redhat.com/errata/RHSA-2010-0095.html"},{"name":"SUSE-SA:2010:005","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html"},{"name":"[oss-security] 20091231 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/12/31/1"},{"name":"oval:org.mitre.oval:def:9702","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9702"},{"name":"RHSA-2010:0020","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0020.html"},{"name":"38031","refsource":"SECUNIA","url":"http://secunia.com/advisories/38031"},{"name":"37523","refsource":"BID","url":"http://www.securityfocus.com/bid/37523"},{"name":"38610","refsource":"SECUNIA","url":"http://secunia.com/advisories/38610"},{"name":"oval:org.mitre.oval:def:7016","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7016"},{"name":"DSA-2005","refsource":"DEBIAN","url":"http://www.debian.org/security/2010/dsa-2005"},{"name":"SUSE-SA:2010:010","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html"},{"name":"RHSA-2010:0041","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0041.html"},{"name":"38492","refsource":"SECUNIA","url":"http://secunia.com/advisories/38492"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-4538","datePublished":"2010-01-12T17:00:00.000Z","dateReserved":"2009-12-31T00:00:00.000Z","dateUpdated":"2024-08-07T07:08:38.032Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-01-12 17:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndIncluding":"2.6.32.3","matchCriteriaId":"B96A7A6C-B8C0-4BAD-B1C1-779C58012EA0"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*","matchCriteriaId":"8C757774-08E7-40AA-B532-6F705C8F7639"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"4538","Ordinal":"1","Title":"CVE-2009-4538","CVE":"CVE-2009-4538","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"4538","Ordinal":"1","NoteData":"drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.","Type":"Description","Title":"CVE-2009-4538"},{"CveYear":"2009","CveId":"4538","Ordinal":"2","NoteData":"2010-01-12","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"4538","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}