CVE-2009-2692
HIGH EXPLOITEDLinux kernel <2.6.30.4, <2.4.37.4 - Privilege Escalation
Title source: llmDescription
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
Exploits (10)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/19933
exploitdb
WORKING POC
VERIFIED
by Ramon de C Valle · textlocallinux
https://www.exploit-db.com/exploits/9598
exploitdb
WORKING POC
VERIFIED
by Ramon de C Valle · textlocallinux
https://www.exploit-db.com/exploits/9641
exploitdb
WORKING POC
VERIFIED
by Przemyslaw Frasunek · textlocallinux
https://www.exploit-db.com/exploits/9436
exploitdb
WORKING POC
VERIFIED
by INetCop Security · clocallinux
https://www.exploit-db.com/exploits/9479
exploitdb
WORKING POC
VERIFIED
by Ramon de C Valle · clocallinux
https://www.exploit-db.com/exploits/9545
metasploit
WORKING POC
GREAT
by Tavis Ormandy, Julien Tinnes <julien at cr0.org>, spender, rcvalle, egypt · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/sock_sendpage.rb
References (39)
... and 19 more
Scores
CVSS v3
7.8
EPSS
0.1602
EPSS Percentile
94.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2026-02-09
Classification
CWE
CWE-908
Status
draft
Affected Products (12)
linux/linux_kernel
< 2.4.37.5
debian/debian_linux
suse/linux_enterprise_real_time
redhat/enterprise_linux_desktop
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_server
redhat/enterprise_linux_server
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_workstation
redhat/enterprise_linux_workstation
Timeline
Published
Aug 14, 2009
Tracked Since
Feb 18, 2026