CVE-2009-0676 is an information disclosure vulnerability in the Linux kernel, specifically affecting versions prior to 2.6.28.6. It stems from the sock_getsockopt function failing to initialize a structure member, allowing local users to expose sensitive kernel memory data. With a CVSS score of 2.1, this vulnerability is of low severity, requiring local access with low attack complexity, and its impact is limited to confidentiality. There is no indication of active exploitation, though a proof-of-concept exploit is available on ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.28.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* | ||
2.6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:* | ||
2.6.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.