Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-0676

17
FAUCET Score

CVE-2009-0676 is an information disclosure vulnerability in the Linux kernel, specifically affecting versions prior to 2.6.28.6. It stems from the sock_getsockopt function failing to initialize a structure member, allowing local users to expose sensitive kernel memory data. With a CVSS score of 2.1, this vulnerability is of low severity, requiring local access with low attack complexity, and its impact is limited to confidentiality. There is no indication of active exploitation, though a proof-of-concept exploit is available on ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.6.28.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
2.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6:*:*:*:*:*:*:*
2.6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*
2.6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*
2.6.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.1LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.70%
Probability of exploitation in next 30 days
EPSS Percentile
49.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-32805 · Feb 20, 2009
This CVE's current EPSS score of 0.0070 is in the 84th percentile among its peer group of 2,096 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: MRG for RHEL-5Fixed in: kernel-rt-0:2.6.24.7-108.el5rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel-0:2.6.9-78.0.22.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-128.1.6.el5
View patch

Vendor Advisories (1)

redhatCVE-2009-0676Moderate

kernel: memory disclosure in SO_BSDCOMPAT gsopt

Feb 11, 2009

References

git.kernel.org
lists.opensuse.org / opensuse-security-announce/2009-04/msg00007.html
lists.opensuse.org / opensuse-security-announce/2009-06/msg00000.html
lists.opensuse.org / opensuse-security-announce/2009-06/msg00001.html
lkml.org / lkml/2009/2/12/123
marc.info
openwall.com / lists/oss-security/2009/02/20/1
patchwork.kernel.org / patch/6816
rhn.redhat.com / errata/RHSA-2009-0459.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/33758
secunia.com / advisories/34394
secunia.com / advisories/34502
secunia.com / advisories/34680
secunia.com / advisories/34786
secunia.com / advisories/34962
secunia.com / advisories/34981
secunia.com / advisories/35011
secunia.com / advisories/35390
secunia.com / advisories/35394
secunia.com / advisories/37471
exchange.xforce.ibmcloud.com / vulnerabilities/48847
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11653
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8618
debian.org / security/2009/dsa-1749
debian.org / security/2009/dsa-1787
debian.org / security/2009/dsa-1794
kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.28.6
mandriva.com / security/advisories
openwall.com / lists/oss-security/2009/02/24/1
openwall.com / lists/oss-security/2009/03/02/6
redhat.com / support/errata/RHSA-2009-0326.html
redhat.com / support/errata/RHSA-2009-0360.html
securityfocus.com / archive/1/507985/100/0/threaded
securityfocus.com / bid/33846
Patch
ubuntu.com / usn/usn-751-1
vmware.com / security/advisories/VMSA-2009-0016.html
vupen.com / english/advisories/2009/3316