CVE-2009-3621
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.0%
from disclosure to weapon19 days
Published on NVDOct 22
1st PoC+19d
exploitation probability
1.0%top 41% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/10022⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git%3Ba=commit%3Bh=77238f2b942b38ab4e7f3aced44084493e4a8675http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://lkml.org/lkml/2009/10/19/50http://patchwork.kernel.org/patch/54678/https://bugzilla.redhat.com/show_bug.cgi?id=529626http://secunia.com/advisories/37086http://secunia.com/advisories/37909