CVE-2005-2709 describes a local denial-of-service vulnerability in the Linux kernel's sysctl functionality, affecting versions prior to 2.6.14.1. A local attacker can trigger a kernel oops, and potentially execute arbitrary code, by manipulating interface files in /proc/sys/net/ipv4/conf/ during interface unregistration. The CVSS score of 4.6 indicates a low-complexity local attack with potential for partial confidentiality, integrity, and availability impact. While no active exploitation is reported and community discussion is minimal, a proof-of-concept exploit exists on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.2.27CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.2.27:*:*:*:*:*:*:* | ||
2.4.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.4.1:*:*:*:*:*:*:* | ||
2.4.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.4.2:*:*:*:*:*:*:* | ||
2.4.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.