cbcvebase.
CVE-2009-1072
published 2009-03-25

CVE-2009-1072: nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create…

medium4.9CVSS 3.1
AVLACLAuNCNICAN
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Affected

25 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
linuxlinux_kernel< 2.6.28.92.6.28.9
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselinux_enterprise_desktop
suselinux_enterprise_server
vmwareesx
vmwareesx
vmwareesx
vmwareesxi
vmwareserver
vmwarevcenter_server
vmwarevirtualcenter
vmwarevirtualcenter
vmwarevma
vmwarevmware_tools
vmwarevmware_vcenter_server
vmwarevmware_vsphere
vmwarevmware_workstation