CVE-2019-9213 is an improper access-control flaw in the Linux kernel prior to 4.20.14. The expand_downwards function in mm/mmap.c does not correctly enforce the minimum mmap address when expanding a downward-growing mapping: its capability check is performed against the wrong task. This can permit mappings in the protected low-address range and makes exploitation of kernel NULL-pointer dereferences easier on platforms that do not implement Supervisor Mode Access Prevention (SMAP).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module that exploits a NULL pointer dereference vulnerability in the Reliable Datagram Sockets (RDS) kernel module (rds.ko) on certain 64-bit Ubuntu Linux systems (CVE-2018-5333, with a MAP_GROWSDOWN mmap_min_addr bypass from CVE-2019-9213). The exploit is local, requiring an existing shell on the target. It checks for the presence of the vulnerable kernel, the RDS module, and the absence of certain security features (SMAP, LKRG, grsecurity). The module uploads and compiles (or drops a precompiled) C exploit on the target, then executes a user-supplied payload (default: Meterpreter reverse shell) as root. The main file is written in Ruby and follows the standard Metasploit module structure, leveraging various Metasploit mixins for file operations, privilege escalation, and payload handling. The only fingerprintable endpoints are the default writable directory (/tmp) and the rds.ko kernel module. The exploit is operational and can be used to gain root privileges on vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel flaw in mmap expand_downwards that lacks a minimum-address check, enabling a NULL-pointer-dereference exploit on platforms without SMAP.
Linux kernel memory-management flaw in expand_downwards that can lead to NULL-pointer dereferences on systems without SMAP.
Linux kernel memory-mapping flaw in expand_downwards caused by a missing mmap minimum-address check, enabling NULL-pointer-dereference exploitation on platforms without SMAP.
An Important-severity Linux kernel mmap flaw in which insufficient enforcement of the minimum mmap address during expand_downwards can allow a process to map the null page. This can make otherwise non-exploitable null-pointer dereferences usable, particularly on non-SMAP platforms.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.