CVE-2009-2698
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.
- Affected products
- Linux Kernel, Red Hat, Suse Linux Enterprise, Vmware Vcenter
- Linux Linux Kernel
- < 2.6.19
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 7.1% (94th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2009-08-27
CVE-2009-2698 at NVD
18 known exploits for CVE-2009-2698
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2009-2698
Linux Kernel < 2.6.19 - udp_sendmsg Local Root Exploit (x86/x64)
Linux Kernel < 2.6.19 udp_sendmsg Local Root Exploit
Linux Kernel 2.6 < 2.6.19 - (32bit) ip_append_data() ring0 Root Exploit
Linux Kernel < 2.6.19 udp_sendmsg Local Root Exploit
Linux Kernel < 2.6.19 udp_sendmsg Local Root Exploit (x86/x64)
Linux Kernel < 2.6.19 udp_sendmsg Local Root Exploit (x86/x64)
Linux Kernel < 2.6.19 udp_sendmsg Local Root Exploit
Linux Kernel 2.6.19 (x86x64) - udp_sendmsg Local Privilege Escalation (2)
Linux Kernel 2.6.19 (Debian 4) - udp_sendmsg Local Privilege Escalation (3)
Linux Kernel < 2.6.19 (x86/x64) - 'udp_sendmsg' Local Privilege Escalation (2)
Linux Kernel < 2.6.19 (Debian 4) - 'udp_sendmsg' Local Privilege Escalation (3)
Linux Kernel 2.6 < 2.6.19 (32bit) ip_append_data() ring0 Root Exploit
Linux Kernel 2.6 < 2.6.19 (32bit) ip_append_data() ring0 Root Exploit
Linux Kernel 2.6 2.6.19 (White Box 4 CentOS 4.44.5 Fedora Core 456 x86) - ip_append_data() Ring0 Privilege Escalation (1)
Linux Kernel 2.6 < 2.6.19 (White Box 4 / CentOS 4.4/4.5 / Fedora Core 4/5/6 x86) - 'ip_append_data()' Ring0 Privilege Escalation (1)
Immunity Canvas: PROTO_OPS_NULL
Linux Kernel udp_sendmsg() MSG_MORE标记本地权限提升漏洞