CVE-2009-3238
Last modified
CVE-2009-3238 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time.". EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | < 2.6.30 | — |
| Canonical | Ubuntu Linux | 6.06 | — |
| Canonical | Ubuntu Linux | 8.04 | — |
| Canonical | Ubuntu Linux | 8.10 | — |
| Canonical | Ubuntu Linux | 9.04 | — |
| Opensuse | Opensuse | 11.0 | — |
| Suse | Linux Enterprise Desktop | 10 | Sp2 |
| Suse | Linux Enterprise Server | 10 | Sp2 |
References
- http://patchwork.kernel.org/patch/21766/Broken Link, Patch
- http://secunia.com/advisories/37105Broken Link
- http://secunia.com/advisories/37351Broken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30Broken Link, Exploit, Vendor Advisory
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=499785Issue Tracking, Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=519692Issue Tracking, Permissions Required
- http://patchwork.kernel.org/patch/21766/Broken Link, Patch
- http://secunia.com/advisories/37105Broken Link
- http://secunia.com/advisories/37351Broken Link
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30Broken Link, Exploit, Vendor Advisory
- http://www.ubuntu.com/usn/USN-852-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=499785Issue Tracking, Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=519692Issue Tracking, Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3238?
How severe is CVE-2009-3238?
How do I fix CVE-2009-3238?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-3232pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and…
- CVE-2009-3233changetrack 4.3 allows local users to execute arbitrary comm…
- CVE-2009-3234Buffer overflow in the perf_copy_attr function in kernel/per…
- CVE-2009-3235Multiple stack-based buffer overflows in the Sieve plugin in…
- CVE-2009-3236The form library in Horde Application Framework 3.2 before 3…
- CVE-2009-3237Multiple cross-site scripting (XSS) vulnerabilities in Horde…
- CVE-2009-3239Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-3240Cross-site scripting (XSS) vulnerability in the Happy Linux …
- CVE-2009-3241Unspecified vulnerability in the OpcUa (OPC UA) dissector in…
- CVE-2009-3242Unspecified vulnerability in packet.c in the GSM A RR dissec…
- CVE-2009-3243Unspecified vulnerability in the TLS dissector in Wireshark …
- CVE-2009-3244Heap-based buffer overflow in the SwDir.dll ActiveX control …
Are you affected by CVE-2009-3238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
