CVE Database
/

CVE-2009-2692

Back to search

CVE-2009-2692

Published: Aug 14, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2009:1233
vendor-advisory
x_refsource_REDHAT
36278
third-party-advisory
x_refsource_SECUNIA
DSA-1865
vendor-advisory
x_refsource_DEBIAN
RHSA-2009:1223
vendor-advisory
x_refsource_REDHAT
37298
third-party-advisory
x_refsource_SECUNIA
36430
third-party-advisory
x_refsource_SECUNIA
37471
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1222
vendor-advisory
x_refsource_REDHAT
19933
exploit
x_refsource_EXPLOIT-DB
ADV-2009-2272
vdb-entry
x_refsource_VUPEN
SUSE-SR:2009:015
vendor-advisory
x_refsource_SUSE
36289
third-party-advisory
x_refsource_SECUNIA
36327
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11591
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:11526
vdb-entry
signature
x_refsource_OVAL
MDVSA-2009:233
vendor-advisory
x_refsource_MANDRIVA
9477
exploit
x_refsource_EXPLOIT-DB
oval:org.mitre.oval:def:8657
vdb-entry
signature
x_refsource_OVAL
36038
vdb-entry
x_refsource_BID
20090818 rPSA-2009-0121-1 kernel open-vm-tools
mailing-list
x_refsource_BUGTRAQ
ADV-2009-3316
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now