PT-2009-5341 · Linux · Linux Kernel
Eugene Teo
+1
·
Published
2009-08-28
·
Updated
2018-11-16
·
CVE-2009-3001
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 2.6.31-rc7
Description:
The issue is related to the
llc ui getname function in the Linux kernel, which does not properly initialize a certain data structure. This allows local users to read the contents of some kernel memory locations by calling getsockname on an AF LLC socket.Recommendations:
For Linux kernel versions prior to 2.6.31-rc7, consider upgrading to a newer version to resolve the issue. As a temporary workaround, restrict access to
AF LLC sockets to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel