{"api_version":"1","generated_at":"2026-07-23T15:42:02+00:00","cve":"CVE-2009-2692","urls":{"html":"https://cve.report/CVE-2009-2692","api":"https://cve.report/api/cve/CVE-2009-2692.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2692","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2692"},"summary":{"title":"CVE-2009-2692","description":"The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-08-14 15:16:27","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-908","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2009/3316","name":"http://www.vupen.com/english/advisories/2009/3316","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/19933","name":"http://www.exploit-db.com/exploits/19933","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Linux Kernel Sendpage Local Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2009-1233.html","name":"http://www.redhat.com/support/errata/RHSA-2009-1233.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36327","name":"http://secunia.com/advisories/36327","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Debian update for linux-2.6 - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2009:015","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8657","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8657","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2009-1222.html","name":"http://rhn.redhat.com/errata/RHSA-2009-1222.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6","name":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/36278","name":"http://secunia.com/advisories/36278","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Linux Kernel Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36289","name":"http://secunia.com/advisories/36289","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Linux Kernel 2.4 Incorrect proto_ops Initialisation NULL Pointer Dereference - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37298","name":"http://secunia.com/advisories/37298","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Avaya Products Linux Kernel Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2009:233","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2009:233","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2009:233 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37471","name":"http://secunia.com/advisories/37471","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"VMware ESX and vMA Update for Multiple Packages - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/505751/100/0/threaded","name":"http://www.securityfocus.com/archive/1/505751/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5","name":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/505912/100/0/threaded","name":"http://www.securityfocus.com/archive/1/505912/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/9477","name":"http://www.exploit-db.com/exploits/9477","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"iMesh <= 7.1.0.x (IMWeb.dll 7.0.0.x) Remote Heap Overflow Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git%3Ba=commit%3Bh=c18d0fe535a73b219f960d1af3d0c264555a12e3","name":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git%3Ba=commit%3Bh=c18d0fe535a73b219f960d1af3d0c264555a12e3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.openwall.com/lists/oss-security/2009/08/14/1","name":"http://www.openwall.com/lists/oss-security/2009/08/14/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch"],"title":"oss-security - CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded","name":"http://www.securityfocus.com/archive/1/507985/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-08/0174.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2009-08/0174.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit"],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.debian.org/security/2009/dsa-1865","name":"http://www.debian.org/security/2009/dsa-1865","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1865-1 linux-2.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/css/P8/documents/100067254","name":"http://support.avaya.com/css/P8/documents/100067254","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"ASA-2009-464 (RHSA-2009-1469)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=516949","name":"https://bugzilla.redhat.com/show_bug.cgi?id=516949","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"],"title":"Bug 516949 – CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36430","name":"http://secunia.com/advisories/36430","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Red Hat update for kernel - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121","name":"http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://issues.rpath.com/browse/RPL-3103","name":"https://issues.rpath.com/browse/RPL-3103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html","name":"http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"],"title":"cr0 blog: Linux NULL pointer dereference due to incorrect proto_ops initializations (CVE-2009-2692)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11526","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11526","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e694958388c50148389b0e9b9e9e8945cf0f1b98","name":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e694958388c50148389b0e9b9e9e8945cf0f1b98","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://grsecurity.net/~spender/wunderbar_emporium.tgz","name":"http://grsecurity.net/~spender/wunderbar_emporium.tgz","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404 Not Found","mime":"application/gzip","httpstatus":"404","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5","name":"http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/2272","name":"http://www.vupen.com/english/advisories/2009/2272","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","name":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"VMSA-2009-0016.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11591","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11591","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2009-1223.html","name":"http://rhn.redhat.com/errata/RHSA-2009-1223.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/512019/100/0/threaded","name":"http://www.securityfocus.com/archive/1/512019/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://zenthought.org/content/file/android-root-2009-08-16-source","name":"http://zenthought.org/content/file/android-root-2009-08-16-source","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404 Not Found","mime":"text/xml","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36038","name":"http://www.securityfocus.com/bid/36038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"],"title":"Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git;a=commit;h=c18d0fe535a73b219f960d1af3d0c264555a12e3","name":"CONFIRM:http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git;a=commit;h=c18d0fe535a73b219f960d1af3d0c264555a12e3","refsource":"MITRE","tags":[],"title":"","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e694958388c50148389b0e9b9e9e8945cf0f1b98","name":"CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e694958388c50148389b0e9b9e9e8945cf0f1b98","refsource":"MITRE","tags":[],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2692","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2692","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2692","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-2692","organization":"Red Hat","lastmodified":"2009-09-14","contributor":"Mark J Cox","statementText":"Red Hat is aware of this issue. Please see http://kbase.redhat.com/faq/docs/DOC-18065. Updates for Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG to correct this issue are available: https://rhn.redhat.com/cve/CVE-2009-2692.html","cve_year":"2009","cve_id":"2692","crc32":"43cd3837"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:59:57.073Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2009:1233","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1233.html"},{"name":"36278","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36278"},{"name":"DSA-1865","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1865"},{"name":"RHSA-2009:1223","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2009-1223.html"},{"name":"20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/512019/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5"},{"name":"37298","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37298"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121"},{"name":"36430","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36430"},{"name":"37471","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37471"},{"name":"RHSA-2009:1222","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2009-1222.html"},{"name":"20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-08/0174.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=516949"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://issues.rpath.com/browse/RPL-3103"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"19933","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/19933"},{"name":"ADV-2009-2272","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/2272"},{"name":"SUSE-SR:2009:015","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"},{"name":"20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/505751/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e694958388c50148389b0e9b9e9e8945cf0f1b98"},{"name":"36289","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36289"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"name":"36327","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36327"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/css/P8/documents/100067254"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://grsecurity.net/~spender/wunderbar_emporium.tgz"},{"name":"oval:org.mitre.oval:def:11591","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11591"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git%3Ba=commit%3Bh=c18d0fe535a73b219f960d1af3d0c264555a12e3"},{"name":"oval:org.mitre.oval:def:11526","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11526"},{"name":"MDVSA-2009:233","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2009:233"},{"name":"9477","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/9477"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6"},{"name":"oval:org.mitre.oval:def:8657","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8657"},{"name":"[oss-security] 20090814 CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/08/14/1"},{"name":"36038","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36038"},{"name":"20090818 rPSA-2009-0121-1 kernel open-vm-tools","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/505912/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://zenthought.org/content/file/android-root-2009-08-16-source"},{"name":"ADV-2009-3316","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3316"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-08-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"RHSA-2009:1233","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1233.html"},{"name":"36278","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36278"},{"name":"DSA-1865","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1865"},{"name":"RHSA-2009:1223","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2009-1223.html"},{"name":"20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/512019/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5"},{"name":"37298","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37298"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121"},{"name":"36430","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36430"},{"name":"37471","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37471"},{"name":"RHSA-2009:1222","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2009-1222.html"},{"name":"20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-08/0174.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=516949"},{"tags":["x_refsource_CONFIRM"],"url":"https://issues.rpath.com/browse/RPL-3103"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"19933","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/19933"},{"name":"ADV-2009-2272","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/2272"},{"name":"SUSE-SR:2009:015","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"},{"name":"20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/505751/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e694958388c50148389b0e9b9e9e8945cf0f1b98"},{"name":"36289","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36289"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"name":"36327","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36327"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/css/P8/documents/100067254"},{"tags":["x_refsource_MISC"],"url":"http://grsecurity.net/~spender/wunderbar_emporium.tgz"},{"name":"oval:org.mitre.oval:def:11591","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11591"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git%3Ba=commit%3Bh=c18d0fe535a73b219f960d1af3d0c264555a12e3"},{"name":"oval:org.mitre.oval:def:11526","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11526"},{"name":"MDVSA-2009:233","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2009:233"},{"name":"9477","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/9477"},{"tags":["x_refsource_MISC"],"url":"http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6"},{"name":"oval:org.mitre.oval:def:8657","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8657"},{"name":"[oss-security] 20090814 CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/08/14/1"},{"name":"36038","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36038"},{"name":"20090818 rPSA-2009-0121-1 kernel open-vm-tools","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/505912/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://zenthought.org/content/file/android-root-2009-08-16-source"},{"name":"ADV-2009-3316","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3316"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2692","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"RHSA-2009:1233","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2009-1233.html"},{"name":"36278","refsource":"SECUNIA","url":"http://secunia.com/advisories/36278"},{"name":"DSA-1865","refsource":"DEBIAN","url":"http://www.debian.org/security/2009/dsa-1865"},{"name":"RHSA-2009:1223","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2009-1223.html"},{"name":"20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/512019/100/0/threaded"},{"name":"http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5"},{"name":"37298","refsource":"SECUNIA","url":"http://secunia.com/advisories/37298"},{"name":"http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121","refsource":"CONFIRM","url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121"},{"name":"36430","refsource":"SECUNIA","url":"http://secunia.com/advisories/36430"},{"name":"37471","refsource":"SECUNIA","url":"http://secunia.com/advisories/37471"},{"name":"RHSA-2009:1222","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2009-1222.html"},{"name":"20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-08/0174.html"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=516949","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=516949"},{"name":"https://issues.rpath.com/browse/RPL-3103","refsource":"CONFIRM","url":"https://issues.rpath.com/browse/RPL-3103"},{"name":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"19933","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/19933"},{"name":"ADV-2009-2272","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/2272"},{"name":"SUSE-SR:2009:015","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"},{"name":"20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/505751/100/0/threaded"},{"name":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e694958388c50148389b0e9b9e9e8945cf0f1b98","refsource":"CONFIRM","url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e694958388c50148389b0e9b9e9e8945cf0f1b98"},{"name":"36289","refsource":"SECUNIA","url":"http://secunia.com/advisories/36289"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"name":"36327","refsource":"SECUNIA","url":"http://secunia.com/advisories/36327"},{"name":"http://support.avaya.com/css/P8/documents/100067254","refsource":"CONFIRM","url":"http://support.avaya.com/css/P8/documents/100067254"},{"name":"http://grsecurity.net/~spender/wunderbar_emporium.tgz","refsource":"MISC","url":"http://grsecurity.net/~spender/wunderbar_emporium.tgz"},{"name":"oval:org.mitre.oval:def:11591","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11591"},{"name":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git;a=commit;h=c18d0fe535a73b219f960d1af3d0c264555a12e3","refsource":"CONFIRM","url":"http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git;a=commit;h=c18d0fe535a73b219f960d1af3d0c264555a12e3"},{"name":"oval:org.mitre.oval:def:11526","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11526"},{"name":"MDVSA-2009:233","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2009:233"},{"name":"9477","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/9477"},{"name":"http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html","refsource":"MISC","url":"http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html"},{"name":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6"},{"name":"oval:org.mitre.oval:def:8657","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8657"},{"name":"[oss-security] 20090814 CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/08/14/1"},{"name":"36038","refsource":"BID","url":"http://www.securityfocus.com/bid/36038"},{"name":"20090818 rPSA-2009-0121-1 kernel open-vm-tools","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/505912/100/0/threaded"},{"name":"http://zenthought.org/content/file/android-root-2009-08-16-source","refsource":"MISC","url":"http://zenthought.org/content/file/android-root-2009-08-16-source"},{"name":"ADV-2009-3316","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/3316"},{"name":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2692","datePublished":"2009-08-14T15:00:00.000Z","dateReserved":"2009-08-05T00:00:00.000Z","dateUpdated":"2024-08-07T05:59:57.073Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-08-14 15:16:27","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-908","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.4.4","versionEndExcluding":"2.4.37.5","matchCriteriaId":"5960758C-4449-4D23-9EA6-92FB031C3725"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.0","versionEndExcluding":"2.6.30.5","matchCriteriaId":"39A91A11-DDAB-4C83-90A4-CFFC7652955E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_real_time:10:*:*:*:*:*:*:*","matchCriteriaId":"AA6CB9DA-D313-4CE9-BB48-6C399156311C"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*","matchCriteriaId":"7D74A418-50F0-42C0-ABBC-BBBE718FF025"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*","matchCriteriaId":"133AAFA7-AF42-4D7B-8822-AA2E85611BF5"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:4.8:*:*:*:*:*:*:*","matchCriteriaId":"7F2976D5-83A5-4A52-A1E6-D0E17F23FD62"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:5.3:*:*:*:*:*:*:*","matchCriteriaId":"941713DB-B1DE-4953-9A9C-174EAFDCB3E6"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server:4.0:*:*:*:*:*:*:*","matchCriteriaId":"73322DEE-27A6-4D18-88A3-ED7F9CAEABD5"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*","matchCriteriaId":"54D669D4-6D7E-449D-80C1-28FA44F06FFE"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server_aus:5.3:*:*:*:*:*:*:*","matchCriteriaId":"1F87B994-28E4-4095-8770-6433DE9C93AB"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_workstation:4.0:*:*:*:*:*:*:*","matchCriteriaId":"5B5DCF29-6830-45FF-BC88-17E2249C653D"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*","matchCriteriaId":"D0AC5CD5-6E58-433C-9EB3-6DFE5656463E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2692","Ordinal":"1","Title":"CVE-2009-2692","CVE":"CVE-2009-2692","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2692","Ordinal":"1","NoteData":"The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.","Type":"Description","Title":"CVE-2009-2692"},{"CveYear":"2009","CveId":"2692","Ordinal":"2","NoteData":"2009-08-14","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"2692","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}