First published: Tue Jul 08 2008(Updated: )
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <2.6.22 | |
Debian Debian Linux | =4.0 | |
Novell Suse Linux Enterprise Server | =10.0-sp2 | |
Novell Suse Linux Enterprise Desktop | =10.0-sp2 | |
Novell Suse Linux Enterprise Server | =10.0-sp1 | |
Novell Suse Linux Enterprise Desktop | =10.0-sp1 | |
openSUSE openSUSE | >=10.3<=11.0 | |
Canonical Ubuntu Linux | =6.06 | |
Canonical Ubuntu Linux | =7.04 | |
Canonical Ubuntu Linux | =7.10 | |
Canonical Ubuntu Linux | =8.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.