kernel: numerous getname() infoleaks
Published Aug 28, 2009
4.9
MEDIUMCVSS 2.0
EPSS 1.03%
Description
The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.
Affected products
No data.
Configuration 1
- < 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
Configuration 2
- 6.06
- 8.04
- 8.10
- 9.04
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-137.el5rt
Fixed · RHSA-2009:1540
Red Hat Enterprise Linux 3
kernel-0:2.4.21-63.EL
Fixed · RHSA-2009:1550
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-137.el5rt | Fixed | RHSA-2009:1540 |
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-63.EL | Fixed | RHSA-2009:1550 |
No package ranges for this CVE.
Remediation
Red Hat statement
CVE-2009-3002 describes a collection of similar information leaks that affect numerous networking protocols. The Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 did not enable support for the AppleTalk DDP protocol, and therefore were not affected by issue (1). The Linux kernel as shipped with Red Hat Enterprise Linux 4, 5 and Red Hat Enterprise MRG did not enable support for IrDA sockets, and therefore were not affected by issue (2). The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG did not enable support for the Acorn Econet and AUN protocols, and therefore were not affected by issue (3). The Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, and Red Hat Enterprise MRG did not enable support for the NET/ROM and ROSE protocols, and therefore were not affected by issues (4) and (5). The raw_getname() leak was introduced in the Linux kernel version 2.6.25-rc1. The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG therefore were not affected by issue (6).
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.03% (0.01029) | 62.41th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.03% (0.01029) | 59.04th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.30% (0.00300) | 51.15th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 12.25th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.04% (0.00044) | 10.48th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.45th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.22% (0.03220) | 84.21th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.22% (0.03220) | 82.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.22% (0.03220) | 65.30th | v2 (v2022.01.01) |
References (27)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=09384dfc76e526c3993c09c42e016372dc9dd22c x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=17ac2e9c58b69a1e25460a568eae1b0dc0188c25 x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3d392475c873c10c10d6d96b94d092a34ebd4791 x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=80922bbb12a105f858a8f0abb879cb4302d0ecaa x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e84b90ae5eb3c112d1f208964df1d8156a538289 x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f6b97b29513950bfbf621a83d85b6f86b39ec8db x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://secunia.com/advisories/36438 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/37105 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/37351 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.exploit-db.com/exploits/9521 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc7 x_refsource_CONFIRMVendor Advisory
- http://www.openwall.com/lists/oss-security/2009/08/27/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/08/27/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/512019/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/36150 vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-852-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-3002 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=519305 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3002
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11611 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11741 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1540.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1550.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-3002
Change history (0)
No recorded changes yet.