CVE-2005-2555
published 2005-08-16CVE-2005-2555: Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct…
PriorityP413medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.45%
36.7th percentile
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2005-08-19
CVE-2005-2548 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
David Howells discovered a local Denial of Service vulnerability in
the key session joining function. Under certain user-triggerable
conditions, a semaphore was not released properly, which caused
processes which also attempted to join a key session to hang forever.
This only affects Ubuntu 5.04 (Hoary Hedgehog). (CAN-2005-2098)
David Howells discovered a local Denial of Service vulnerability in
the keyring allocator. A local attacker could exploit this to crash
the kernel by attempting to add a specially crafted invalid keyring.
This only affects Ubuntu 5.04 (Hoary Hedgehog). (CAN-2005-2099)
Balazs Scheidler discovered a local Denial of Service vulnerability in
the xfrm_compile_policy() function. By calling sets
Red Hat
security flaw
vendor_redhat·2005-08-06·CVSS 4.6
CVE-2005-2555 [MEDIUM] security flaw
security flaw
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
GHSA
GHSA-mmch-mw53-ff45: Linux kernel 2
ghsa_unreviewed·2022-05-01
CVE-2005-2555 [MEDIUM] GHSA-mmch-mw53-ff45: Linux kernel 2
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-2555 security flaw
bugzilla·2018-08-16·CVSS 4.6
CVE-2005-2555 [MEDIUM] CVE-2005-2555 security flaw
CVE-2005-2555 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
Bugzilla
CVE-2005-2555 IPSEC lacks restrictions
bugzilla·2005-08-17·CVSS 4.6
CVE-2005-2555 [MEDIUM] CVE-2005-2555 IPSEC lacks restrictions
CVE-2005-2555 IPSEC lacks restrictions
This issue does not affect linux 2.4 but affects Red Hat Enterprise Linux 3 as
it contains a backport of this functionality.
+++ This bug was initially created as a clone of Bug #166131 +++
A flaw was discovered where xfrm_user_policy was not protected by CAP_NET_ADMIN.
A local unprivileged user could use this flaw to bypass or create IPSEC
policies. This is not believed to allow privilege escalation, but could lead to
a denial of service (since there is no upper bounds on creating policies).
A fix was committed to 2.6 to correct this issue:
http://linux.bkbits.net:8080/linux-2.6/cset@42f783aesxFQlEEg0e9GPi4oeVDHbA
Discussion:
Created attachment 117852
jwltest-sock-policy-cap.patch
---
Test kernels available here:
http://people.redhat.com/li
Bugzilla
Multiple Kernel vulnerabilities
bugzilla·2005-05-11
[MEDIUM] Multiple Kernel vulnerabilities
Multiple Kernel vulnerabilities
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Mozilla rulez!)
Description of problem:
Paul Starzetz of iSEC has found yet another bug in binfmt_elf.c. It can be abused to crash the kernel, perhaps even to break into the kernel land. See the advisory for details.
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Steps to Reproduce:
Additional info:
I've got a quick and dirty patch. I'll submit it ASAP.
Discussion:
Grr...Bugzilla assigned the bug to [email protected] rather than to
[email protected]
---
Created attachment 114264
The patch for CAN-2005-1263
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
This patch can be applied to FL kernel 2.4.20-43:
402e548b02382c015d6f5e5704370a1ba546598b
li
http://secunia.com/advisories/17002http://secunia.com/advisories/17073http://secunia.com/advisories/17826http://secunia.com/advisories/19369http://secunia.com/advisories/19374http://www.debian.org/security/2006/dsa-1017http://www.debian.org/security/2006/dsa-1018http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2http://www.mandriva.com/security/advisories?name=MDKSA-2005:218http://www.mandriva.com/security/advisories?name=MDKSA-2005:219http://www.novell.com/linux/security/advisories/2005_50_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2005-514.htmlhttp://www.redhat.com/support/errata/RHSA-2005-663.htmlhttp://www.securityfocus.com/archive/1/427980/100/0/threadedhttp://www.securityfocus.com/bid/14609http://www.vupen.com/english/advisories/2005/1878https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10444https://usn.ubuntu.com/169-1/http://secunia.com/advisories/17002http://secunia.com/advisories/17073http://secunia.com/advisories/17826http://secunia.com/advisories/19369http://secunia.com/advisories/19374http://www.debian.org/security/2006/dsa-1017http://www.debian.org/security/2006/dsa-1018http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2http://www.mandriva.com/security/advisories?name=MDKSA-2005:218http://www.mandriva.com/security/advisories?name=MDKSA-2005:219http://www.novell.com/linux/security/advisories/2005_50_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2005-514.htmlhttp://www.redhat.com/support/errata/RHSA-2005-663.htmlhttp://www.securityfocus.com/archive/1/427980/100/0/threadedhttp://www.securityfocus.com/bid/14609http://www.vupen.com/english/advisories/2005/1878https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10444https://usn.ubuntu.com/169-1/
2005-08-16
Published