Candidate: CVE-2009-2768 Description: The new credentials code broke load_flat_shared_library() as it now uses an uninitialized cred pointer, leading to a NULL pointer dereference. References: http://lkml.org/lkml/2009/6/22/91 http://thread.gmane.org/gmane.linux.hardware.blackfin.kernel.devel/1905 Ubuntu-Description: Notes: Bugs: upstream: released (2.6.31-rc6) [3440625d78711bee41a84cf29c3d8c579b522666] linux-2.6: released (2.6.30-6) [bugfix/all/flat-fix-uninitialized-ptr-with-shared-libs.patch] 2.6.18-etch-security: N/A "kernel/cred.c introduced in 2.6.29" 2.6.24-etch-security: N/A "kernel/cred.c introduced in 2.6.29" 2.6.26-lenny-security: N/A "kernel/cred.c introduced in 2.6.29" 2.6.15-dapper-security: 2.6.22-gutsy-security: 2.6.24-hardy-security: 2.6.27-intrepid-security: