vendor:
Kernel
by:
p0c73n1
7,2
CVSS
HIGH
Linux kernel 2.6 < 2.6.19 (32bit) ip_append_data() local ring0 root exploit
264
CWE
Product Name: Kernel
Affected Version From: 2.6
Affected Version To: 2.6.19
Patch Exists: YES
Related CWE: CVE-2009-2698
CPE: 2.6:2.6.19
Metasploit:
https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0010-cve-2009-2698/, https://www.rapid7.com/db/vulnerabilities/vmsa-2009-0016-5-updated-service-console-package-kernel-cve-2009-2698/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-2698/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1233/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-2698/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1457/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: White Box 4(2.6.9-5.ELsmp), CentOS 4.4(2.6.9-42.ELsmp), CentOS 4.5(2.6.9-55.ELsmp), Fedora Core 4(2.6.11-1.1369_FC4smp), Fedora Core 5(2.6.15-1.2054_FC5), Fedora Core 6(2.6.18-1.2798.fc6)
2009
0x82-CVE-2009-2698
This exploit is a local ring0 root exploit for Linux kernel 2.6 < 2.6.19 (32bit). It was tested on White Box 4(2.6.9-5.ELsmp), CentOS 4.4(2.6.9-42.ELsmp), CentOS 4.5(2.6.9-55.ELsmp), Fedora Core 4(2.6.11-1.1369_FC4smp), Fedora Core 5(2.6.15-1.2054_FC5), Fedora Core 6(2.6.18-1.2798.fc6). It was discovered by Tavis Ormandy and Julien Tinnes of the Google Security Team. The exploit was written by p0c73n1(at)gmail(dot)com.
Mitigation:
Apply the latest security patches and updates to the system.