CVE Vulnerabilities

CVE-2008-2931

Improper Privilege Management

Published: Jul 09, 2008 | Modified: Feb 13, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux * 2.6.22 (excluding)
Red Hat Enterprise Linux 5 RedHat kernel-0:2.6.18-92.1.13.el5 *
Linux-source-2.6.15 Ubuntu dapper *
Linux-source-2.6.20 Ubuntu feisty *

Potential Mitigations

References