CVE-2009-1072
published 2009-03-25CVE-2009-1072: nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNICAN
EPSS
0.43%
35.0th percentile
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.28.9 | 2.6.28.9 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | server | — | — |
| vmware | vcenter_server | — | — |
| vmware | virtualcenter | — | — |
| vmware | virtualcenter | — | — |
| vmware | vma | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:N
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-07-02·CVSS 4.9
CVE-2009-1242 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Igor Zhbanov discovered that NFS clients were able to create device nodes
even when root_squash was enabled. An authenticated remote attacker
could create device nodes with open permissions, leading to a loss of
privacy or escalation of privileges. Only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1072)
Dan Carpenter discovered that SELinux did not correctly handle
certain network checks when running with compat_net=1. A local
attacker could exploit this to bypass network checks. Default Ubuntu
installations do not enable SELinux, and only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1184)
Shaohua Li discovered that memory was not correctly initialized in the
AGP subsystem. A local attacker could potentially re
Red Hat
kernel: nfsd should drop CAP_MKNOD for non-root
vendor_redhat·2009-03-19·CVSS 4.9
CVE-2009-1072 [MEDIUM] kernel: nfsd should drop CAP_MKNOD for non-root
kernel: nfsd should drop CAP_MKNOD for non-root
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
Statement: This issue is not planned to be fixed in Red Hat Enterprise Linux 2.1 and 3, due to these products being in Production 3 of their maintenance life-cycles, where only qualified security errata of important or critical impact are addressed.
GHSA
GHSA-pxr6-gr2r-cc6x: nfsd in the Linux kernel before 2
ghsa_unreviewed·2022-05-02
CVE-2009-1072 [MEDIUM] GHSA-pxr6-gr2r-cc6x: nfsd in the Linux kernel before 2
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root [rhel-4.9]
bugzilla·2009-05-20·CVSS 4.9
CVE-2009-1072 [MEDIUM] CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root [rhel-4.9]
CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root [rhel-4.9]
This bug has been copied from bug #499074 and has been proposed
to be backported to 4.8 z-stream (EUS).
Discussion:
Committed in 89.0.1.EL
---
*** This bug has been marked as a duplicate of bug 499073 ***
Bugzilla
CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root
bugzilla·2009-03-23·CVSS 4.9
CVE-2009-1072 [MEDIUM] CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root
CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root
Description of problem:
Since creating a device node is normally an operation requiring special privilege, Igor Zhbanov points out that it is surprising (to say the least) that a client can, for example, create a device node on a filesystem exported with root_squash.
So, make sure CAP_MKNOD is among the capabilities dropped when an nfsd thread handles a request from a non-root user.
References:
http://groups.google.com/group/fa.linux.kernel/browse_thread/thread/665b99fdc970bee3
http://article.gmane.org/gmane.comp.security.oss.general/1581
Discussion:
Created attachment 336238
Upstream patch
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=76a67ec6fb79ff3570dcb5342142c16098299911
---
This is
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=76a67ec6fb79ff3570dcb5342142c16098299911http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://secunia.com/advisories/34422http://secunia.com/advisories/34432http://secunia.com/advisories/34786http://secunia.com/advisories/35121http://secunia.com/advisories/35185http://secunia.com/advisories/35343http://secunia.com/advisories/35390http://secunia.com/advisories/35394http://secunia.com/advisories/35656http://secunia.com/advisories/37471http://thread.gmane.org/gmane.linux.kernel/805280http://www.debian.org/security/2009/dsa-1800http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9http://www.openwall.com/lists/oss-security/2009/03/23/1http://www.redhat.com/support/errata/RHSA-2009-1081.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34205http://www.ubuntu.com/usn/usn-793-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/0802http://www.vupen.com/english/advisories/2009/3316https://exchange.xforce.ibmcloud.com/vulnerabilities/49356https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10314https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8382http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=76a67ec6fb79ff3570dcb5342142c16098299911http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://secunia.com/advisories/34422http://secunia.com/advisories/34432http://secunia.com/advisories/34786http://secunia.com/advisories/35121http://secunia.com/advisories/35185http://secunia.com/advisories/35343http://secunia.com/advisories/35390http://secunia.com/advisories/35394http://secunia.com/advisories/35656http://secunia.com/advisories/37471http://thread.gmane.org/gmane.linux.kernel/805280http://www.debian.org/security/2009/dsa-1800http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9http://www.openwall.com/lists/oss-security/2009/03/23/1http://www.redhat.com/support/errata/RHSA-2009-1081.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34205http://www.ubuntu.com/usn/usn-793-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/0802http://www.vupen.com/english/advisories/2009/3316https://exchange.xforce.ibmcloud.com/vulnerabilities/49356https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10314https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8382
2009-03-25
Published