LWN.net Logo

kernel: unprivileged user driver vulnerability

Package(s):kernel CVE #(s):CVE-2009-3889 CVE-2009-3939
Created:December 3, 2009 Updated:March 3, 2010
Description: From the Red Hat alert:

Permission issues were found in the megaraid_sas driver (for SAS based RAID controllers) in the Linux kernel. The "dbg_lvl" and "poll_mode_io" files on the sysfs file system ("/sys/") had world-writable permissions. This could allow local, unprivileged users to change the behavior of the driver. (CVE-2009-3889, CVE-2009-3939, Moderate)

Alerts:
SuSE SUSE-SA:2010:014 2010-03-03
Red Hat RHSA-2010:0076-01 2010-02-02
Debian DSA-2004-1 2010-02-27
SuSE SUSE-SA:2010:013 2010-02-18
Debian DSA-1996-1 2010-02-12
SuSE SUSE-SA:2010:010 2010-02-08
CentOS CESA-2010:0046 2010-01-20
Red Hat RHSA-2010:0046-01 2010-01-19
SuSE SUSE-SA:2010:005 2010-01-15
SuSE SUSE-SA:2010:012 2010-02-15
CentOS CESA-2010:0076 2010-02-04
SuSE SUSE-SA:2010:001 2010-01-07
SuSE SUSE-SA:2009:064 2009-12-22
SuSE SUSE-SA:2009:061 2009-12-14
Ubuntu USN-864-1 2009-12-05
Red Hat RHSA-2009:1635-01 2009-12-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds