cbcvebase.
CVE-2009-3556
published 2010-01-27

CVE-2009-3556: A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization…

PriorityP411low1.9CVSS 2.0
AVLACMAuNCNIPAN
EPSS
0.38%
30.5th percentile
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.

Affected

2 ranges
VendorProductVersion rangeFixed in
linuxlinux_kernel
redhatenterprise_linux

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.