PoC Index

CVE-2009-2698

HIGH 7.8EPSS 7.1%

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
7.12% chance of exploitation in the next 30 days, 94th percentile
Published
2009-08-27
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (3)

Exploit collections (1)

References

Related