The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | * | 2.6.22 (excluding) |
Red Hat Enterprise Linux 5 | RedHat | kernel-0:2.6.18-92.1.13.el5 | * |
Linux-source-2.6.15 | Ubuntu | dapper | * |
Linux-source-2.6.20 | Ubuntu | feisty | * |