peter bassill · operator
$ cve CVE-2009-2692 JSON

CVE-2009-2692 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 14.6% (pctl 97)

Patch early

A public exploit exists.

Description

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS14.63% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-908
On CISA KEVno
Public exploityes
Published2009-08-14
Last modified2026-06-16

Affected (8)

VendorProduct
debiandebian linux
linuxlinux kernel
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
suselinux enterprise real time

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD