CVE-2009-2909

Linux Kernel < 2.6.31.1 - Numeric Error

Title source: rule

Description

Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation.

Scores

EPSS 0.0004
EPSS Percentile 13.2%

Classification

CWE
CWE-189
Status draft

Affected Products (50)

linux/linux_kernel < 2.6.31.1
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Oct 20, 2009
Tracked Since Feb 18, 2026