nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | * | 2.6.28.9 (excluding) |
MRG for RHEL-5 | RedHat | kernel-rt-0:2.6.24.7-117.el5rt | * |
Red Hat Enterprise Linux 4 | RedHat | kernel-0:2.6.9-89.0.3.EL | * |
Red Hat Enterprise Linux 5 | RedHat | kernel-0:2.6.18-128.1.14.el5 | * |
Linux | Ubuntu | hardy | * |
Linux | Ubuntu | intrepid | * |
Linux | Ubuntu | jaunty | * |
Linux-source-2.6.15 | Ubuntu | dapper | * |
Linux-source-2.6.22 | Ubuntu | gutsy | * |