CVE-2009-2692
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
- Affected products
- Linux Kernel, Red Hat
- Linux Linux Kernel
- < 2.4.37.5, 2.6.30.5
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 14.6% (96th percentile)
- Weakness
- CWE-908
- NVD status
- Modified
- Published
- 2009-08-14
CVE-2009-2692 at NVD
25 known exploits for CVE-2009-2692
Proof-of-concept code and exploit modules indexed by Sploitus
Linux_Exploit_Suggester
CVE-2009-2692
kioptrix-level1-writeup
Linux Kernel 2.4/2.6 - sock_sendpage() ring0 Root Exploit (Simple Version)
Linux Kernel 2.x - sock_sendpage() Local Root Exploit (Android Edition)
Linux Kernel Sendpage Local Privilege Escalation
[Linux Exploit Suggester] Grab the Linux Operating Systems release version, and return a suggestive list of possible exploits
Linux Kernel Sendpage Local Privilege Escalation
Linux Kernel Sendpage Local Privilege Escalation
Linux Kernel 2.4.4 < 2.4.37.4 / 2.6.0 < 2.6.30.4 - 'Sendpage' Local Privilege Escalation (Metasploit)
Linux Kernel Sendpage Local Privilege Escalation
Linux Kernel 2.4/2.6 - 'sock_sendpage()' Local Privilege Escalation (3)
Linux Kernel 2.4/2.6 (Fedora 11) - 'sock_sendpage()' Local Privilege Escalation (2)
Linux Kernel 2.4.x/2.6.x (CentOS 4.8/5.3 / RHEL 4.8/5.3 / SuSE 10 SP2/11 / Ubuntu 8.10) (PPC) - 'sock_sendpage()' Local Privilege Escalation
Immunity Canvas: PROTO_OPS_NULL
Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver)
Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver)
Linux Kernel 2.42.6 (RedHat Linux 9 Fedora Core 4 11 Whitebox 4 CentOS 4) - sock_sendpage() Ring0 Privilege Escalation (5)
Linux Kernel 2.4/2.6 (RedHat Linux 9 / Fedora Core 4 < 11 / Whitebox 4 / CentOS 4) - 'sock_sendpage()' Ring0 Privilege Escalation (5)
Linux Kernel 2.x sock_sendpage() Local Root Exploit (Android Edition)
Linux Kernel 2.x sock_sendpage() Local Root Exploit (Android Edition)
Linux Kernel 2.x (Android) - sock_sendpage() Local Privilege Escalation
Linux Kernel 2.x (Android) - 'sock_sendpage()' Local Privilege Escalation
Linux Kernel 2.x - 'sock_sendpage()' Local Privilege Escalation (4)
Linux Kernel 2.x (RedHat) - 'sock_sendpage()' Ring0 Privilege Escalation (1)