/[kernel-sec]/retired/CVE-2009-1072
ViewVC logotype

Contents of /retired/CVE-2009-1072

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1732 - (show annotations) (download)
Sun Feb 14 21:07:42 2010 UTC (3 years, 3 months ago) by jmm
File size: 922 byte(s)
retire issues
1 Candidate: CVE-2009-1072
2 Description:
3 nfsd in the Linux kernel before 2.6.28.9 does not drop the
4 CAP_MKNOD capability before handling a user request in a
5 thread, which allows local users to create device nodes, as
6 demonstrated on a filesystem that has been exported with
7 the root_squash option.
8 References:
9 http://thread.gmane.org/gmane.linux.kernel/805280
10 http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=76a67ec6fb79ff3570dcb5342142c16098299911
11 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9
12 Ubuntu-Description:
13 Notes:
14 Bugs:
15 upstream: released (2.6.28.9, 2.6.29)
16 linux-2.6: released (2.6.29-1)
17 2.6.18-etch-security: ignored (EOL)
18 2.6.24-etch-security: ignored (EOL)
19 2.6.26-lenny-security: released (2.6.26-15lenny1) [bugfix/all/nfsd-drop-CAP_MKNOD-for-non-root.patch]
20 2.6.15-dapper-security:
21 2.6.22-gutsy-security:
22 2.6.24-hardy-security:
23 2.6.27-intrepid-security:

  ViewVC Help
Powered by ViewVC 1.1.5