CVE-2009-3001

Linux Kernel < 2.6.31 - Information Disclosure

Title source: rule

Description

The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jon Oberheide · clocallinux
https://www.exploit-db.com/exploits/9513

Scores

EPSS 0.0009
EPSS Percentile 24.9%

Details

CWE
CWE-200
Status published
Products (6)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
canonical/ubuntu_linux 9.04
linux/linux_kernel 2.6.31 (7 CPE variants)
linux/linux_kernel < 2.6.31
Published Aug 28, 2009
Tracked Since Feb 18, 2026