Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2692

Опубликовано: 13 авг. 2009
Источник: redhat
CVSS2: 7.2

Описание

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

Отчет

Red Hat is aware of this issue. Please see https://access.redhat.com/articles/18053.

Дополнительная информация

Статус:

Important
Дефект:
CWE-456->CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=516949kernel: uninit op in SOCKOPS_WRAP() leads to privesc

7.2 High

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 16 лет назад

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

CVSS3: 7.8
nvd
почти 16 лет назад

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

CVSS3: 7.8
debian
почти 16 лет назад

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, d ...

CVSS3: 7.8
github
около 3 лет назад

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

oracle-oval
почти 16 лет назад

ELSA-2009-1222: kernel security and bug fix update (IMPORTANT)

7.2 High

CVSS2