imPC@ndo IT

Tracker / CVE-2009-2698

CVE-2009-2698

High 7.8

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.

Affected products and versions

canonical ubuntu_linux
fedoraproject fedora
linux linux_kernel · … → 2.6.19
redhat enterprise_linux_desktop
redhat enterprise_linux_eus
redhat enterprise_linux_server
redhat enterprise_linux_server_aus
redhat enterprise_linux_workstation
suse linux_enterprise_desktop
suse linux_enterprise_server
vmware esxi
vmware vcenter_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References