CVE-2009-1072: Medium severity Linux Linux kernel vulnerability
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAPMKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the rootsquash option.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1072?
CVE-2009-1072 has been rated as a medium severity vulnerability due to its potential to allow local users to create device nodes.
How do I fix CVE-2009-1072?
To fix CVE-2009-1072, update the affected Linux kernel to version 2.6.28.9 or later.
Which versions of Linux are affected by CVE-2009-1072?
CVE-2009-1072 affects Linux kernel versions prior to 2.6.28.9 and several older versions of openSUSE, Debian, and Ubuntu.
What type of attack is CVE-2009-1072 associated with?
CVE-2009-1072 is associated with local privilege escalation attacks through unauthorized device node creation.
Is CVE-2009-1072 exploitable over the network?
CVE-2009-1072 is not exploitable over the network as it requires local user access to the affected system.