CVE-2009-2692

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.05 % (18th)
0.05% Progress
Affected Products 8
Advisories 11

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

Weaknesses
CWE-908
Use of Uninitialized Resource
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2009-08-14 15:16:27
(15 years ago)
Updated Date
2024-02-08 23:50:03
(7 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.4.4 version and prior 2.4.37.5 version cpe:2.3:o:linux:linux_kernel >= 2.4.4 < 2.4.37.5
  Linux Kernel from 2.6.0 version and prior 2.6.30.5 version cpe:2.3:o:linux:linux_kernel >= 2.6.0 < 2.6.30.5

Configuration #2

    CPE23 From Up To
  Debian Linux 4.0 cpe:2.3:o:debian:debian_linux:4.0

Configuration #3

    CPE23 From Up To
  Suse Linux Enterprise Real Time 10 cpe:2.3:o:suse:linux_enterprise_real_time:10

Configuration #4

    CPE23 From Up To
  Redhat Enterprise Linux Desktop 4.0 cpe:2.3:o:redhat:enterprise_linux_desktop:4.0
  Redhat Enterprise Linux Desktop 5.0 cpe:2.3:o:redhat:enterprise_linux_desktop:5.0
  Redhat Enterprise Linux Eus 4.8 cpe:2.3:o:redhat:enterprise_linux_eus:4.8
  Redhat Enterprise Linux Eus 5.3 cpe:2.3:o:redhat:enterprise_linux_eus:5.3
  Redhat Enterprise Linux Server 4.0 cpe:2.3:o:redhat:enterprise_linux_server:4.0
  Redhat Enterprise Linux Server 5.0 cpe:2.3:o:redhat:enterprise_linux_server:5.0
  Redhat Enterprise Linux Server Aus 5.3 cpe:2.3:o:redhat:enterprise_linux_server_aus:5.3
  Redhat Enterprise Linux Workstation 4.0 cpe:2.3:o:redhat:enterprise_linux_workstation:4.0
  Redhat Enterprise Linux Workstation 5.0 cpe:2.3:o:redhat:enterprise_linux_workstation:5.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...