CVE-2009-1072
Publication date 25 March 2009
Last updated 24 July 2024
Ubuntu priority
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | 9.04 jaunty |
Fixed 2.6.28-13.45
|
8.10 intrepid |
Fixed 2.6.27-14.35
|
|
8.04 LTS hardy |
Fixed 2.6.24-24.55
|
|
7.10 gutsy | Not in release | |
6.06 LTS dapper | Not in release | |
linux-source-2.6.15 | 9.04 jaunty | Not in release |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
6.06 LTS dapper |
Fixed 2.6.15-54.77
|
|
linux-source-2.6.22 | 9.04 jaunty | Not in release |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Ignored end of life, was needs-triage | |
6.06 LTS dapper | Not in release |