CVE-2008-2931

The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.22
debiandebian_linux
4.0
novellsuse_linux_enterprise_desktop
10.0:sp1
novellsuse_linux_enterprise_desktop
10.0:sp2
novellsuse_linux_enterprise_server
10.0:sp1
novellsuse_linux_enterprise_server
10.0:sp2
opensuseopensuse
10.3 ≤
𝑥
≤ 11.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
7.04
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
hardy
not-affected
gutsy
dne
feisty
dne
dapper
dne
linux-source-2.6.15
hardy
dne
gutsy
dne
feisty
dne
dapper
Fixed 2.6.15-52.71
released
linux-source-2.6.20
hardy
dne
gutsy
dne
feisty
Fixed 2.6.20-17.39
released
dapper
dne
linux-source-2.6.22
hardy
dne
gutsy
not-affected
feisty
dne
dapper
dne
References