HIGH · 7.8

CVE-2009-2698

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NU...

Vulnerability Description

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel< 2.6.19
CanonicalUbuntu Linux6.06
SuseLinux Enterprise Desktop10
SuseLinux Enterprise Server9
FedoraprojectFedora10
RedhatEnterprise Linux Desktop4.0
RedhatEnterprise Linux Eus4.8
RedhatEnterprise Linux Server4.0
RedhatEnterprise Linux Server Aus5.3
RedhatEnterprise Linux Workstation4.0
VmwareVcenter Server4.0
VmwareEsxi4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2698?

CVE-2009-2698 is a vulnerability with a CVSS score of 7.8 (HIGH). The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NU...

How severe is CVE-2009-2698?

CVE-2009-2698 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2698?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server, Fedoraproject Fedora.