CVE-2009-3725: High severity linux kernel vulnerability
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAPSYSADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3725?
CVE-2009-3725 is rated as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2009-3725?
To fix CVE-2009-3725, update the Linux kernel to version 2.6.31.5 or later.
Which Linux kernel versions are affected by CVE-2009-3725?
CVE-2009-3725 affects Linux kernel versions prior to 2.6.31.5.
Who is impacted by CVE-2009-3725?
Local users of affected Linux systems can exploit CVE-2009-3725 to gain elevated privileges.
What systems specifically are vulnerable to CVE-2009-3725?
Distributions like Ubuntu Linux versions 6.06, 8.04, 8.10, 9.04, and 9.10 are vulnerable to CVE-2009-3725.