VDB

CVE-2009-3238

CVE-2009-3238 PUBLISHED CVSS 7.800000190734863 HIGH

The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."

EPSS 1.63% · 74.0th percentile

Risk Scores

CVSS 2.0
7.800000190734863
EPSS Score
1.63%
74.0th percentile

Affected Products

VendorProductVersions
canonicalubuntu_linux9.04, 6.06, 8.04
suselinux_enterprise_desktop10
linuxlinux_kernel0
opensuseopensuse11.0
suselinux_enterprise_server10
n/an/an/a

Timeline

  • Sep 18, 2009 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›