LOW · 2.1

CVE-2009-2910

arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register val...

Vulnerability Description

arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel< 2.6.31.4
SuseLinux Enterprise Debuginfo10
OpensuseOpensuse11.0
SuseLinux Enterprise Desktop10
SuseLinux Enterprise Server9
SuseLinux Enterprise Software Development Kit10
CanonicalUbuntu Linux6.06
RedhatVirtualization5
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus5.4
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Workstation5.0
FedoraprojectFedora10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2910?

CVE-2009-2910 is a vulnerability with a CVSS score of 2.1 (LOW). arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register val...

How severe is CVE-2009-2910?

CVE-2009-2910 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2910?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Suse Linux Enterprise Debuginfo, Opensuse Opensuse, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server.