udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
The product does not properly verify that the source of data or communication is valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Udev | Udev_project | * | 141 (excluding) |
| Red Hat Enterprise Linux 5 | RedHat | udev-0:095-14.20.el5_3 | * |
| Udev | Ubuntu | dapper | * |
| Udev | Ubuntu | gutsy | * |
| Udev | Ubuntu | hardy | * |
| Udev | Ubuntu | intrepid | * |
| Udev | Ubuntu | upstream | * |