CVE-2009-0676

Linux Kernel < 2.6.28.6 - Information Disclosure via SO_BSDCOMPAT getsockopt Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0676. PoCs published by Clément Lecigne.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in the Linux Kernel by leveraging improperly initialized memory in the SO_BSDCOMPAT getsockopt operation. It reads uninitialized kernel memory and prints it, potentially exposing sensitive data.

Description

The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Clément Lecigne · clocallinux
https://www.exploit-db.com/exploits/32805

This exploit demonstrates an information disclosure vulnerability in the Linux Kernel by leveraging improperly initialized memory in the SO_BSDCOMPAT getsockopt operation. It reads uninitialized kernel memory and prints it, potentially exposing sensitive data.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Linux Kernel versions prior to 2.6.28.8
No auth needed
Prerequisites: Access to a vulnerable Linux Kernel system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (38)

Core 38
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35390
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48847
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2009/02/20/1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34502
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0326.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34786
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34962
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8618
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37471
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0360.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2009-0459.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/03/02/6
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1749
Various Sources x_refsource_confirm
http://patchwork.kernel.org/patch/6816/
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1794
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=linux-kernel&m=123540732700371&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33758
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-751-1
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11653
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33846
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35011
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507985/100/0/threaded
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/02/24/1
Various Sources mailing-list x_refsource_mlist
http://lkml.org/lkml/2009/2/12/123
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34981
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34394
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=486305
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1787
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:071
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34680
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3316
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35394

Scores

EPSS 0.0070
EPSS Percentile 48.2%

Details

CWE
CWE-264
Status published
Products (50)
linux/linux_kernel 2.6
linux/linux_kernel 2.6.0
linux/linux_kernel 2.6.1
linux/linux_kernel 2.6.2
linux/linux_kernel 2.6.3
linux/linux_kernel 2.6.4
linux/linux_kernel 2.6.5
linux/linux_kernel 2.6.6
linux/linux_kernel 2.6.7
linux/linux_kernel 2.6.8
... and 40 more
Published Feb 22, 2009
Tracked Since Feb 18, 2026