CVE-2009-3725
published 2009-11-06CVE-2009-3725: The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2)…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.61%
45.9th percentile
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| drbd8 | drbd8 | — | — |
| linbit | drbd8 | — | — |
| linux | linux_kernel | < 2.6.31.5 | 2.6.31.5 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-479j-8mrp-jf68: The connector layer in the Linux kernel before 2
ghsa_unreviewed·2022-05-02
CVE-2009-3725 [HIGH] GHSA-479j-8mrp-jf68: The connector layer in the Linux kernel before 2
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.
GHSA
GHSA-44pr-cm9p-mffx: drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725
ghsa_unreviewed·2022-04-21·CVSS 7.2
CVE-2010-0747 [HIGH] GHSA-44pr-cm9p-mffx: drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-12-05·CVSS 4.9
CVE-2009-3726 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the AX.25 network subsystem did not correctly
check integer signedness in certain setsockopt calls. A local attacker
could exploit this to crash the system, leading to a denial of service.
Ubuntu 9.10 was not affected. (CVE-2009-2909)
Jan Beulich discovered that the kernel could leak register contents to
32-bit processes that were switched to 64-bit mode. A local attacker
could run a specially crafted binary to read register values from an
earlier process, leading to a loss of privacy. (CVE-2009-2910)
Dave Jones discovered that the gdth SCSI driver did not correctly validate
array indexes in certain ioctl calls. A local attacker could exploit
this to crash the system or gain elevated privil
Red Hat
CVE-2010-0747: drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725
vendor_redhat·CVSS 7.2
CVE-2010-0747 [HIGH] CVE-2010-0747: drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.
Statement: Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG as they did not backport an out-of-tree drbd module (drbd8).
Red Hat
CVE-2009-3725: The connector layer in the Linux kernel before 2
vendor_redhat·CVSS 7.2
CVE-2009-3725 [HIGH] CVE-2009-3725: The connector layer in the Linux kernel before 2
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.
Statement: Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 or Red Hat Enterprise MRG, as they do not include the upstream change introducing this flaw.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=linux-kernel&m=125449888416314&w=2http://marc.info/?l=oss-security&m=125715484511380&w=2http://marc.info/?l=oss-security&m=125716192622235&w=2http://patchwork.kernel.org/patch/51382/http://patchwork.kernel.org/patch/51383/http://patchwork.kernel.org/patch/51384/http://patchwork.kernel.org/patch/51387/http://secunia.com/advisories/37113http://secunia.com/advisories/38905http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5http://www.securityfocus.com/bid/36834http://www.ubuntu.com/usn/usn-864-1http://xorl.wordpress.com/2009/10/31/linux-kernel-multiple-capabilities-missing-checks/http://marc.info/?l=linux-kernel&m=125449888416314&w=2http://marc.info/?l=oss-security&m=125715484511380&w=2http://marc.info/?l=oss-security&m=125716192622235&w=2http://patchwork.kernel.org/patch/51382/http://patchwork.kernel.org/patch/51383/http://patchwork.kernel.org/patch/51384/http://patchwork.kernel.org/patch/51387/http://secunia.com/advisories/37113http://secunia.com/advisories/38905http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5http://www.securityfocus.com/bid/36834http://www.ubuntu.com/usn/usn-864-1http://xorl.wordpress.com/2009/10/31/linux-kernel-multiple-capabilities-missing-checks/
2009-11-06
Published