CVE-2009-2692 is a local privilege escalation vulnerability affecting Linux kernel versions 2.6.0 through 2.6.30.4 and 2.4.4 through 2.4.37.4, including various Debian, Red Hat, and SUSE distributions. It stems from uninitialized function pointers in socket operation structures, allowing a local attacker to trigger a NULL pointer dereference and execute arbitrary code by mapping page zero. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and can lead to full compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including Metasploit modules and multiple ExploitDB entries, indicating a high potential for exploitation, though it is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.4, < 2.4.37.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 2.6.0, < 2.6.30.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_real_time:10:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.