Vulnerability Database

289,782

Total vulnerabilities in the database

CVE-2009-3002

The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.

  • Published: Aug 28, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-3002
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.9
  • AV:L/AC:L/Au:N/C:C/I:N/A:N

CWEs:

Software From Fixed in
linux / linux_kernel 2.6.31-rc4 2.6.31-rc4.x
linux / linux_kernel 2.6.31-rc1 2.6.31-rc1.x
linux / linux_kernel 2.6.31-rc6 2.6.31-rc6.x
linux / linux_kernel 2.6.31-rc5 2.6.31-rc5.x
linux / linux_kernel 2.6.31-rc3 2.6.31-rc3.x
linux / linux_kernel 2.6.31-rc2 2.6.31-rc2.x
linux / linux_kernel 2.6.31 2.6.31.x
linux / linux_kernel - 2.6.31
canonical / ubuntu_linux 6.06 6.06.x
canonical / ubuntu_linux 9.04 9.04.x
canonical / ubuntu_linux 8.04 8.04.x
canonical / ubuntu_linux 8.10 8.10.x