CVE-2009-3621 is a local denial-of-service vulnerability affecting Linux kernel versions 2.6.31.4 and earlier, including distributions from Canonical, Fedora, openSUSE, SUSE, and VMware. An attacker can exploit this by creating a specific type of AF_UNIX socket, shutting it down, and then repeatedly connecting to it, leading to a system hang. With a CVSS score of 5.5 (Medium), it requires local access and low attack complexity to achieve high availability impact. While not listed in CISA's KEV catalog and showing no active exploitation or significant community discussion, a public exploit (EDB-10022) exists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.31.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:* | ||
8.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:* | ||
9.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.