REDHAT-BUG-555238: Low severity netfilter ebtables vulnerability
Description of problem: commit dce766af541f6605fa9889892c0280bab31c66ab Author: Florian Westphal <fwestphal> Date: Fri Jan 8 17:31:24 2010 +0100
netfilter: ebtables: enforce CAPNETADMIN normal users are currently allowed to set/modify ebtables rules. Restrict it to processes with CAPNETADMIN. Note that this cannot be reproduced with unmodified ebtables binary because it uses SOCKRAW. Signed-off-by: Florian Westphal <fwestphal> Cc: stable Signed-off-by: Patrick McHardy <kaber>
Upstream commit: http://git.kernel.org/linus/dce766af541f6605fa9889892c0280bab31c66ab
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A normal user process that can issue the relevant ebtables rule-setting or modification operations is exposed. The issue allows such operations without requiring CAP_NET_ADMIN.
Does use of the standard ebtables binary demonstrate the problem?
No. The description states that the issue cannot be reproduced with an unmodified ebtables binary because that binary uses SOCK_RAW.
What authorization check addresses the issue?
Rule-setting and rule-modification operations should be restricted to processes with CAP_NET_ADMIN.