2.1
CVSSv2

CVE-2009-0676

Published: 22/02/2009 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The sock_getsockopt function in net/core/sock.c in the Linux kernel prior to 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.27.12

linux linux kernel 2.6.20.6

linux linux kernel 2.6.28

linux linux kernel 2.6.25.4

linux linux kernel 2.6.25.11

linux linux kernel 2.6.20.9

linux linux kernel 2.6.26

linux linux kernel 2.6.18

linux linux kernel 2.6.11

linux linux kernel 2.6.25.9

linux linux kernel 2.6.23.4

linux linux kernel 2.6.22.15

linux linux kernel 2.6.16.16

linux linux kernel 2.6.18.7

linux linux kernel 2.6.17.12

linux linux kernel 2.6.16.39

linux linux kernel 2.6.27.3

linux linux kernel 2.6.21

linux linux kernel 2.6.16.9

linux linux kernel 2.6.17.9

linux linux kernel 2.6.11.2

linux linux kernel 2.6.27.1

linux linux kernel 2.6.5

linux linux kernel 2.6.15.3

linux linux kernel 2.6.11.10

linux linux kernel 2.6.24.7

linux linux kernel 2.6.1

linux linux kernel 2.6.16.43

linux linux kernel 2.6.16.6

linux linux kernel 2.6.16.8

linux linux kernel 2.6.20.13

linux linux kernel 2.6.22.4

linux linux kernel 2.6.14.7

linux linux kernel 2.6.13

linux linux kernel 2.6.17.2

linux linux kernel 2.6.13.3

linux linux kernel 2.6.23.13

linux linux kernel 2.6.11.8

linux linux kernel 2.6.24.2

linux linux kernel 2.6.26.5

linux linux kernel 2.6.16.34

linux linux kernel 2.6.25.20

linux linux kernel 2.6.22.21

linux linux kernel 2.6.25.12

linux linux kernel 2.6.23.7

linux linux kernel

linux linux kernel 2.6.17.8

linux linux kernel 2.6.14.4

linux linux kernel 2.6.14

linux linux kernel 2.6.25.5

linux linux kernel 2.6.17.4

linux linux kernel 2.6.16.18

linux linux kernel 2.6.17.14

linux linux kernel 2.6.10

linux linux kernel 2.6.23.8

linux linux kernel 2.6.25

linux linux kernel 2.6.27

linux linux kernel 2.6.16.45

linux linux kernel 2.6.22.12

linux linux kernel 2.6.25.18

linux linux kernel 2.6.14.3

linux linux kernel 2.6.24

linux linux kernel 2.6.18.3

linux linux kernel 2.6.25.8

linux linux kernel 2.6.16.37

linux linux kernel 2.6.11.6

linux linux kernel 2.6.16.48

linux linux kernel 2.6.11.11

linux linux kernel 2.6.16.13

linux linux kernel 2.6.27.10

linux linux kernel 2.6.3

linux linux kernel 2.6.21.6

linux linux kernel 2.6.26.6

linux linux kernel 2.6.22.1

linux linux kernel 2.6.16.4

linux linux kernel 2.6.23.16

linux linux kernel 2.6.17.3

linux linux kernel 2.6.24.1

linux linux kernel 2.6.20.5

linux linux kernel 2.6.25.6

linux linux kernel 2.6.22

linux linux kernel 2.6.28.4

linux linux kernel 2.6.4

linux linux kernel 2.6.16.15

linux linux kernel 2.6.15.6

linux linux kernel 2.6.26.3

linux linux kernel 2.6.20.16

linux linux kernel 2.6.15.1

linux linux kernel 2.6.11.5

linux linux kernel 2.6.28.2

linux linux kernel 2.6.19.3

linux linux kernel 2.6.27.4

linux linux kernel 2.6.19.4

linux linux kernel 2.6.25.13

linux linux kernel 2.6.19.1

linux linux kernel 2.6.18.4

linux linux kernel 2.6.16.1

linux linux kernel 2.6.18.1

linux linux kernel 2.6.20.21

linux linux kernel 2.6.23.1

linux linux kernel 2.6.2

linux linux kernel 2.6.14.5

linux linux kernel 2.6.13.2

linux linux kernel 2.6.25.7

linux linux kernel 2.6.17.5

linux linux kernel 2.6.18.5

linux linux kernel 2.6.21.1

linux linux kernel 2.6.16.32

linux linux kernel 2.6.13.5

linux linux kernel 2.6.16.57

linux linux kernel 2.6.16.49

linux linux kernel 2.6.25.3

linux linux kernel 2.6.17

linux linux kernel 2.6.19.2

linux linux kernel 2.6.26.2

linux linux kernel 2.6.21.4

linux linux kernel 2.6.16.11

linux linux kernel 2.6.20.17

linux linux kernel 2.6.16.14

linux linux kernel 2.6.20.12

linux linux kernel 2.6.16.25

linux linux kernel 2.6.16.21

linux linux kernel 2.6.16.33

linux linux kernel 2.6.8

linux linux kernel 2.6.16.28

linux linux kernel 2.6.17.10

linux linux kernel 2.6.21.5

linux linux kernel 2.6.25.15

linux linux kernel 2.6.14.1

linux linux kernel 2.6.23.15

linux linux kernel 2.6.16.23

linux linux kernel 2.6.12.5

linux linux kernel 2.6.15.7

linux linux kernel 2.6.20

linux linux kernel 2.6.23.10

linux linux kernel 2.6.22.7

linux linux kernel 2.6.16.3

linux linux kernel 2.6.27.8

linux linux kernel 2.6.26.1

linux linux kernel 2.6.25.19

linux linux kernel 2.6.20.20

linux linux kernel 2.6.16.36

linux linux kernel 2.6.14.6

linux linux kernel 2.6.12.1

linux linux kernel 2.6.27.9

linux linux kernel 2.6.11.9

linux linux kernel 2.6.16.46

linux linux kernel 2.6.17.1

linux linux kernel 2.6.20.8

linux linux kernel 2.6.20.15

linux linux kernel 2.6.22.18

linux linux kernel 2.6.0

linux linux kernel 2.6.16.54

linux linux kernel 2.6.13.4

linux linux kernel 2.6.22.20

linux linux kernel 2.6.23

linux linux kernel 2.6.20.18

linux linux kernel 2.6.23.9

linux linux kernel 2.6.22.6

linux linux kernel 2.6.23.3

linux linux kernel 2.6.18.8

linux linux kernel 2.6.22.3

linux linux kernel 2.6.12.2

linux linux kernel 2.6.16.31

linux linux kernel 2.6.16.26

linux linux kernel 2.6.16.62

linux linux kernel 2.6.25.2

linux linux kernel 2.6.18.2

linux linux kernel 2.6.25.1

linux linux kernel 2.6.16.29

linux linux kernel 2.6.24.4

linux linux kernel 2.6.25.16

linux linux kernel 2.6.22.9

linux linux kernel 2.6.25.17

linux linux kernel 2.6.20.11

linux linux kernel 2.6.19

linux linux kernel 2.6.20.3

linux linux kernel 2.6.16

linux linux kernel 2.6.28.3

linux linux kernel 2.6.22.13

linux linux kernel 2.6.19.7

linux linux kernel 2.6.21.3

linux linux kernel 2.6.24.5

linux linux kernel 2.6.24_rc1

linux linux kernel 2.6.16.51

linux linux kernel 2.6.15.2

linux linux kernel 2.6.20.19

linux linux kernel 2.6.16.22

linux linux kernel 2.6.22.17

linux linux kernel 2.6.16.58

linux linux kernel 2.6.16.40

linux linux kernel 2.6.16.47

linux linux kernel 2.6.16.42

linux linux kernel 2.6.23.14

linux linux kernel 2.6.17.11

linux linux kernel 2.6.16.10

linux linux kernel 2.6.12.4

linux linux kernel 2.6.16.41

linux linux kernel 2.6.16.52

linux linux kernel 2.6.11.3

linux linux kernel 2.6.20.10

linux linux kernel 2.6.16.24

linux linux kernel 2.6.25.10

linux linux kernel 2.6.22.11

linux linux kernel 2.6.16.55

linux linux kernel 2.6.12.3

linux linux kernel 2.6.22.10

linux linux kernel 2.6.23.17

linux linux kernel 2.6.27.5

linux linux kernel 2.6.23.2

linux linux kernel 2.6.7

linux linux kernel 2.6.21.7

linux linux kernel 2.6.16.30

linux linux kernel 2.6.21.2

linux linux kernel 2.6.15.4

linux linux kernel 2.6.27.7

linux linux kernel 2.6.16.59

linux linux kernel 2.6.16.38

linux linux kernel 2.6.16.17

linux linux kernel 2.6.26.8

linux linux kernel 2.6.20.2

linux linux kernel 2.6.22.22

linux linux kernel 2.6.16.12

linux linux kernel 2.6.16.27

linux linux kernel 2.6.16.53

linux linux kernel 2.6.12.6

linux linux kernel 2.6.17.7

linux linux kernel 2.6.20.1

linux linux kernel 2.6.11.7

linux linux kernel 2.6.16.2

linux linux kernel 2.6.24.6

linux linux kernel 2.6.18.6

linux linux kernel 2.6.22_rc7

linux linux kernel 2.6.15

linux linux kernel 2.6.16.44

linux linux kernel 2.6.23.12

linux linux kernel 2.6.16.35

linux linux kernel 2.6.19.6

linux linux kernel 2.6.16.50

linux linux kernel 2.6.23.5

linux linux kernel 2.6.22.8

linux linux kernel 2.6.14.2

linux linux kernel 2.6.16.61

linux linux kernel 2.6.19.5

linux linux kernel 2.6.20.4

linux linux kernel 2.6.17.6

linux linux kernel 2.6.23.6

linux linux kernel 2.6.27.2

linux linux kernel 2.6.16.7

linux linux kernel 2.6.17.13

linux linux kernel 2.6.16.60

linux linux kernel 2.6.22.2

linux linux kernel 2.6.8.1

linux linux kernel 2.6.27.11

linux linux kernel 2.6.16.56

linux linux kernel 2.6.22.19

linux linux kernel 2.6.24.3

linux linux kernel 2.6.22_rc1

linux linux kernel 2.6.20.14

linux linux kernel 2.6.22.5

linux linux kernel 2.6.25.14

linux linux kernel 2.6.20.7

linux linux kernel 2.6.28.1

linux linux kernel 2.6.16.5

linux linux kernel 2.6.11.4

linux linux kernel 2.6.26.4

linux linux kernel 2.6.16.19

linux linux kernel 2.6.27.6

linux linux kernel 2.6.26.7

linux linux kernel 2.6.11.12

linux linux kernel 2.6.16.20

linux linux kernel 2.6.15.5

linux linux kernel 2.6.22.16

linux linux kernel 2.6.11.1

linux linux kernel 2.6.9

linux linux kernel 2.6.13.1

linux linux kernel 2.6.23.11

linux linux kernel 2.6.22.14

linux linux kernel 2.6.6

linux linux kernel 2.6

linux linux kernel 2.6.12

Vendor Advisories

Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix several security issues and several bugsare now available for Red Hat Enterprise Linux 5This update has been rated as having important security impact by the RedHat Secur ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix several security issues and various bugsare now available for Red Hat Enterprise Linux 4This update has been rated as having important security impact by the RedHat Secur ...
NFS did not correctly handle races between fcntl and interrupts A local attacker on an NFS mount could consume unlimited kernel memory, leading to a denial of service (CVE-2008-4307) ...
NFS did not correctly handle races between fcntl and interrupts A local attacker on an NFS mount could consume unlimited kernel memory, leading to a denial of service Ubuntu 810 was not affected (CVE-2008-4307) ...
Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0029 Christian Borntraeger discovered an issue effecting the alpha, mips, powerpc, s390 and sparc64 architectures that al ...
Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-4307 Bryn M Reeves reported a denial of service in the NFS filesystem Local users can trigger a kernel BUG() due to a r ...

Exploits

/* source: wwwsecurityfocuscom/bid/33846/info The Linux Kernel is prone to an information-disclosure vulnerability because it fails to properly initialize certain memory before using using it in a user-accessible operation Successful exploits will allow attackers to view portions of kernel memory Information harvested may be used in fu ...

References

CWE-264http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.6http://lkml.org/lkml/2009/2/12/123http://patchwork.kernel.org/patch/6816/http://www.securityfocus.com/bid/33846https://bugzilla.redhat.com/show_bug.cgi?id=486305http://openwall.com/lists/oss-security/2009/02/20/1http://www.openwall.com/lists/oss-security/2009/03/02/6http://marc.info/?l=linux-kernel&m=123540732700371&w=2http://www.openwall.com/lists/oss-security/2009/02/24/1http://www.mandriva.com/security/advisories?name=MDVSA-2009:071http://www.debian.org/security/2009/dsa-1749http://www.redhat.com/support/errata/RHSA-2009-0360.htmlhttp://secunia.com/advisories/34394http://secunia.com/advisories/33758http://www.redhat.com/support/errata/RHSA-2009-0326.htmlhttp://secunia.com/advisories/34502http://www.ubuntu.com/usn/usn-751-1http://secunia.com/advisories/34680http://secunia.com/advisories/34786http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.htmlhttp://www.debian.org/security/2009/dsa-1787http://secunia.com/advisories/34962http://secunia.com/advisories/34981http://rhn.redhat.com/errata/RHSA-2009-0459.htmlhttp://secunia.com/advisories/35011http://www.debian.org/security/2009/dsa-1794http://secunia.com/advisories/35390http://secunia.com/advisories/35394http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.htmlhttp://www.vupen.com/english/advisories/2009/3316http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://secunia.com/advisories/37471https://exchange.xforce.ibmcloud.com/vulnerabilities/48847https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8618https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11653http://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=df0bca049d01c0ee94afb7cd5dfd959541e6c8dahttps://access.redhat.com/errata/RHSA-2009:0326https://nvd.nist.govhttps://usn.ubuntu.com/752-1/https://www.exploit-db.com/exploits/32805/