CVE-2009-1072
Publication date 25 March 2009
Last updated 24 July 2024
Ubuntu priority
Description
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| linux | ||
| linux-source-2.6.15 | ||
| linux-source-2.6.22 | ||