CVE-2009-3556
published 2010-01-27CVE-2009-3556: A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization…
PriorityP411low1.9CVSS 2.0
AVLACMAuNCNIPAN
EPSS
0.38%
30.5th percentile
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3g2r-q9r9-rjh5: A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2
ghsa_unreviewed·2022-05-02
CVE-2009-3556 [LOW] GHSA-3g2r-q9r9-rjh5: A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.
Red Hat
kernel: qla2xxx NPIV vport management pseudofiles are world writable
vendor_redhat·2010-01-19·CVSS 1.9
CVE-2009-3556 [LOW] CWE-732 kernel: qla2xxx NPIV vport management pseudofiles are world writable
kernel: qla2xxx NPIV vport management pseudofiles are world writable
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG. Shipped kernels do not include upstream commit d025c9db that introduced the problem.
This upstream commit was backported in Red Hat Enterprise Linux 5 via RHBA-2008:0314 update. Issue was add
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.htmlhttp://support.avaya.com/css/P8/documents/100073666http://www.openwall.com/lists/oss-security/2010/01/20/2https://bugzilla.redhat.com/show_bug.cgi?id=537177https://exchange.xforce.ibmcloud.com/vulnerabilities/55809https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6744https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9738https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.htmlhttp://support.avaya.com/css/P8/documents/100073666http://www.openwall.com/lists/oss-security/2010/01/20/2https://bugzilla.redhat.com/show_bug.cgi?id=537177https://exchange.xforce.ibmcloud.com/vulnerabilities/55809https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6744https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9738https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.html
2010-01-27
Published