Candidate: CVE-2009-0322 PublicDate: 2009-01-28 18:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0322 https://ubuntu.com/security/notices/USN-751-1 https://ubuntu.com/security/notices/USN-752-1 Description: drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/. Ubuntu-Description: The Dell platform device did not correctly validate user parameters. A local attacker could perform specially crafted reads to crash the system, leading to a denial of service. Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_linux-source-2.6.15: upstream_linux-source-2.6.15: needs-triage dapper_linux-source-2.6.15: released (2.6.15-54.76) gutsy_linux-source-2.6.15: DNE hardy_linux-source-2.6.15: DNE intrepid_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux-source-2.6.22: upstream_linux-source-2.6.22: needs-triage dapper_linux-source-2.6.22: DNE gutsy_linux-source-2.6.22: released (2.6.22-16.62) hardy_linux-source-2.6.22: DNE intrepid_linux-source-2.6.22: DNE devel_linux-source-2.6.22: DNE Patches_linux: upstream_linux: needs-triage dapper_linux: DNE gutsy_linux: DNE hardy_linux: released (2.6.24-23.52) intrepid_linux: released (2.6.27-11.31) devel_linux: not-affected