← Back

CVE-2009-3001

nvd nist
Published: Aug 28, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.9
Vector
AV:L/AC:L/Au:N/C:C/I:N/A:N
Exploitability: 3.9 / Impact: 6.9
Source: NVD

Description

The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.

Affected (12)

1 product
Linux Kernel
1 product
Ubuntu Linux
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Before 2.6.31
Version 2.6.31
Version 2.6.31 rc1
Version 2.6.31 rc2
Version 2.6.31 rc3
Version 2.6.31 rc4
Version 2.6.31 rc5
Version 2.6.31 rc6
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 6.06
Version 8.04
Version 8.10
Version 9.04

References (18)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.