LWN.net Logo

kernel: privilege escalation

Package(s):kernel CVE #(s):CVE-2009-1072
Created:April 16, 2009 Updated:July 2, 2009
Description: The kernel has a privilege escalation vulnerability. From the SUSE alert:

nfsd in the Linux kernel does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Alerts:
Ubuntu USN-793-1 2009-07-02
Red Hat RHSA-2009:1132-01 2009-06-30
CentOS CESA-2009:1106 2009-06-19
Red Hat RHSA-2009:1106-01 2009-06-16
SuSE SUSE-SA:2009:033 2009-06-16
SuSE SUSE-SA:2009:031 2009-06-09
SuSE SUSE-SA:2009:030 2009-06-08
Red Hat RHSA-2009:1081-01 2009-06-03
SuSE SUSE-SA:2009:028 2009-05-20
Debian DSA-1800-1 2009-05-15
SuSE SUSE-SA:2009:021 2009-04-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds