Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-2692

53
FAUCET Score

CVE-2009-2692 is a local privilege escalation vulnerability affecting Linux kernel versions 2.6.0 through 2.6.30.4 and 2.4.4 through 2.4.37.4, including various Debian, Red Hat, and SUSE distributions. It stems from uninitialized function pointers in socket operation structures, allowing a local attacker to trigger a NULL pointer dereference and execute arbitrary code by mapping page zero. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and can lead to full compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including Metasploit modules and multiple ExploitDB entries, indicating a high potential for exploitation, though it is not currently listed on the CISA KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.4.4, < 2.4.37.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 2.6.0, < 2.6.30.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_real_time:10:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
14.63%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Metasploit: Linux Kernel Sendpage Local Privilege Escalation · Aug 13, 2009
ExploitDB: EDB-19933 · Jul 19, 2012
This CVE's current EPSS score of 0.1463 is in the 99th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: MRG for RHEL-5Fixed in: kernel-rt-0:2.6.24.7-132.el5rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: kernel-0:2.4.21-60.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel-0:2.6.9-89.0.9.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4.7 Z StreamFixed in: kernel-0:2.6.9-78.0.27.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-128.7.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.2 Z StreamFixed in: kernel-0:2.6.18-92.1.28.el5
View patch

Vendor Advisories (1)

redhatCVE-2009-2692Important

kernel: uninit op in SOCKOPS_WRAP() leads to privesc

Aug 13, 2009

References

archives.neohapsis.com / archives/fulldisclosure/2009-08/0174.html
Broken LinkExploit
blog.cr0.org / 2009/08/linux-null-pointer-dereference-due-to.html
ExploitIssue Tracking
git.kernel.org
Broken Link
git.kernel.org
Broken Link
grsecurity.net / ~spender/wunderbar_emporium.tgz
Broken Link
lists.opensuse.org / opensuse-security-announce/2009-09/msg00001.html
Mailing List
rhn.redhat.com / errata/RHSA-2009-1222.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2009-1223.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatch
secunia.com / advisories/36278
Broken LinkVendor Advisory
secunia.com / advisories/36289
Broken LinkVendor Advisory
secunia.com / advisories/36327
Broken LinkVendor Advisory
secunia.com / advisories/36430
Broken LinkVendor Advisory
secunia.com / advisories/37298
Broken LinkVendor Advisory
secunia.com / advisories/37471
Broken LinkVendor Advisory
issues.rpath.com / browse/RPL-3103
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11526
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11591
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8657
Broken Link
support.avaya.com / css/P8/documents/100067254
Third Party Advisory
wiki.rpath.com / wiki/Advisories:rPSA-2009-0121
Broken Link
debian.org / security/2009/dsa-1865
Mailing ListThird Party Advisory
exploit-db.com / exploits/19933
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/9477
Third Party AdvisoryVDB Entry
kernel.org / pub/linux/kernel/v2.4/ChangeLog-2.4.37.5
Broken LinkVendor Advisory
kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.30.5
Broken LinkVendor Advisory
kernel.org / pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6
Broken LinkVendor Advisory
mandriva.com / security/advisories
Broken Link
openwall.com / lists/oss-security/2009/08/14/1
Mailing ListPatch
redhat.com / support/errata/RHSA-2009-1233.html
Broken Link
securityfocus.com / archive/1/505751/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/505912/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/507985/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/512019/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/36038
Broken LinkExploitThird Party AdvisoryVDB Entry
vmware.com / security/advisories/VMSA-2009-0016.html
Third Party Advisory
vupen.com / english/advisories/2009/2272
Broken LinkPatchVendor Advisory
vupen.com / english/advisories/2009/3316
Broken LinkVendor Advisory
zenthought.org / content/file/android-root-2009-08-16-source
Broken Link