|
|
| |
|
| |
kernel: privilege escalation
| Package(s): | kernel |
CVE #(s): | CVE-2009-1072
|
| Created: | April 16, 2009 |
Updated: | July 2, 2009 |
| Description: |
The kernel has a privilege escalation vulnerability.
From the SUSE alert:
nfsd in the Linux kernel does not drop the CAP_MKNOD
capability before handling a user request in a thread, which allows
local users to create device nodes, as demonstrated on a filesystem
that has been exported with the root_squash option. |
| Alerts: |
|
( Log in to post comments)
|
|
|