CVE-2009-3001
Linux Kernel < 2.6.31 - Information Disclosure
Title source: ruleDescription
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Jon Oberheide · clocallinux
https://www.exploit-db.com/exploits/9513
References (9)
Scores
EPSS
0.0009
EPSS Percentile
24.9%
Classification
CWE
CWE-200
Status
draft
Affected Products (12)
linux/linux_kernel
< 2.6.31
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
Timeline
Published
Aug 28, 2009
Tracked Since
Feb 18, 2026