peter bassill · operator
$ cve CVE-2009-2698 JSON

CVE-2009-2698 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS7.12% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-476
On CISA KEVno
Public exploityes
Published2009-08-27
Last modified2026-06-16

Affected (12)

VendorProduct
canonicalubuntu linux
fedoraprojectfedora
linuxlinux kernel
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise server
vmwareesxi
vmwarevcenter server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD