Sploitus

CVE-2009-2692

25 known exploits for CVE-2009-2692

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

Affected products
Linux Kernel, Red Hat
Linux Linux Kernel
< 2.4.37.5, 2.6.30.5
CVSS 3.1
7.8 HIGH
EPSS
14.6% (96th percentile)
Weakness
CWE-908
NVD status
Modified
Published
2009-08-14
CVE-2009-2692 at NVD
Authoritative description, scoring and affected products

25 known exploits for CVE-2009-2692

Proof-of-concept code and exploit modules indexed by Sploitus

Linux_Exploit_Suggester
2026-08-28 KitPloitKITPLOIT
CVE-2009-2692
2026-08-26 KitPloitKITPLOIT
kioptrix-level1-writeup
2026-07-13 8Prashant88GITHUB
Linux Kernel 2.4/2.6 - sock_sendpage() ring0 Root Exploit (Simple Version)
2014-07-01 RootSEEBUG
Linux Kernel 2.x - sock_sendpage() Local Root Exploit (Android Edition)
2014-07-01 RootSEEBUG
Linux Kernel Sendpage Local Privilege Escalation
2013-10-09 Tavis Ormandy, Julien Tinnes <julien at cr0.org>, spender, rcvalle, egypt <egypt@metasploit.com>METASPLOITRuby
[Linux Exploit Suggester] Grab the Linux Operating Systems release version, and return a suggestive list of possible exploits
2013-08-29 KitPloitKITPLOIT
Linux Kernel Sendpage Local Privilege Escalation
2012-07-20 RootSEEBUGRuby
Linux Kernel Sendpage Local Privilege Escalation
2012-07-19 metasploitZDTRuby
Linux Kernel 2.4.4 < 2.4.37.4 / 2.6.0 < 2.6.30.4 - 'Sendpage' Local Privilege Escalation (Metasploit)
2012-07-19 MetasploitEXPLOITDBRuby
Linux Kernel Sendpage Local Privilege Escalation
2012-07-19 Brad SpenglerPACKETSTORMRuby
Linux Kernel 2.4/2.6 - 'sock_sendpage()' Local Privilege Escalation (3)
2009-09-11 Ramon de C ValleEXPLOITDB
Linux Kernel 2.4/2.6 (Fedora 11) - 'sock_sendpage()' Local Privilege Escalation (2)
2009-09-09 Ramon de C ValleEXPLOITDB
Linux Kernel 2.4.x/2.6.x (CentOS 4.8/5.3 / RHEL 4.8/5.3 / SuSE 10 SP2/11 / Ubuntu 8.10) (PPC) - 'sock_sendpage()' Local Privilege Escalation
2009-08-31 Ramon de C ValleEXPLOITDBC
Immunity Canvas: PROTO_OPS_NULL
2009-08-27 Immunity CanvasCANVAS
Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver)
2009-08-25 RootSEEBUG
Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver)
2009-08-24 INetCop SecurityZDTC
Linux Kernel 2.42.6 (RedHat Linux 9 Fedora Core 4 11 Whitebox 4 CentOS 4) - sock_sendpage() Ring0 Privilege Escalation (5)
2009-08-24 INetCop SecurityEXPLOITPACKC
Linux Kernel 2.4/2.6 (RedHat Linux 9 / Fedora Core 4 < 11 / Whitebox 4 / CentOS 4) - 'sock_sendpage()' Ring0 Privilege Escalation (5)
2009-08-24 INetCop SecurityEXPLOITDBC
Linux Kernel 2.x sock_sendpage() Local Root Exploit (Android Edition)
2009-08-19 RootSEEBUG
Linux Kernel 2.x sock_sendpage() Local Root Exploit (Android Edition)
2009-08-18 ZinxZDT
Linux Kernel 2.x (Android) - sock_sendpage() Local Privilege Escalation
2009-08-18 ZinxEXPLOITPACK
Linux Kernel 2.x (Android) - 'sock_sendpage()' Local Privilege Escalation
2009-08-18 ZinxEXPLOITDB
Linux Kernel 2.x - 'sock_sendpage()' Local Privilege Escalation (4)
2009-08-14 Przemyslaw FrasunekEXPLOITDB
Linux Kernel 2.x (RedHat) - 'sock_sendpage()' Ring0 Privilege Escalation (1)
2009-08-14 spenderEXPLOITDB