CVE-2009-0675 describes a logic error in the Linux kernel's skfp_ioctl function (skfddi.c) affecting versions prior to 2.6.28.6. This flaw allows local users to reset driver statistics by incorrectly permitting SKFP_CLR_STATS requests when the CAP_NET_ADMIN capability is absent, rather than present. The vulnerability has a low CVSS score of 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N), indicating local access, low complexity, and only a partial impact on integrity (resetting statistics). There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.28.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* | ||
2.6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:* | ||
2.6.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.