Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-1265

17
FAUCET Score

CVE-2009-1265 describes an integer overflow vulnerability in the rose_sendmsg function within the Linux kernel (versions 2.6.24.4 and prior to 2.6.30-rc1). This flaw allows remote attackers to potentially obtain sensitive information by providing a large length value, leading to the transmission of uninitialized memory. The vulnerability has a CVSS score of 5.0, indicating a medium severity risk with a network attack vector and low attack complexity, resulting in a potential compromise of confidentiality. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
2.6.24.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.24.4:*:*:*:*:*:*:*
2.6.24.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.24.5:*:*:*:*:*:*:*
2.6.24.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.24.6:*:*:*:*:*:*:*
2.6.24.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.24.7:*:*:*:*:*:*:*
2.6.25CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.25:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.17%
Probability of exploitation in next 30 days
EPSS Percentile
86.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0317 is in the 82nd percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2009-1265

CVE-2009-1265

References

bugzilla.kernel.org / show_bug.cgi
Exploit
git.kernel.org
lists.opensuse.org / opensuse-security-announce/2009-05/msg00002.html
lists.opensuse.org / opensuse-security-announce/2009-06/msg00000.html
lists.opensuse.org / opensuse-security-announce/2009-06/msg00001.html
lists.opensuse.org / opensuse-security-announce/2009-06/msg00002.html
osvdb.org / 53571
osvdb.org / 53630
osvdb.org / 53631
secunia.com / advisories/34981
Vendor Advisory
secunia.com / advisories/35011
Vendor Advisory
secunia.com / advisories/35121
Vendor Advisory
secunia.com / advisories/35185
Vendor Advisory
secunia.com / advisories/35387
Vendor Advisory
secunia.com / advisories/35390
Vendor Advisory
secunia.com / advisories/35394
Vendor Advisory
secunia.com / advisories/35656
Vendor Advisory
debian.org / security/2009/dsa-1787
debian.org / security/2009/dsa-1794
debian.org / security/2009/dsa-1800
mandriva.com / security/advisories
mandriva.com / security/advisories
openwall.com / lists/oss-security/2009/04/08/2
securityfocus.com / bid/34654
ubuntu.com / usn/usn-793-1