CVE-2008-2931
09.07.2008, 18:41
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 < 2.6.22 |
debian | debian_linux | 4.0 |
novell | suse_linux_enterprise_desktop | 10.0:sp1 |
novell | suse_linux_enterprise_desktop | 10.0:sp2 |
novell | suse_linux_enterprise_server | 10.0:sp1 |
novell | suse_linux_enterprise_server | 10.0:sp2 |
opensuse | opensuse | 10.3 ≤ 𝑥 ≤ 11.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 7.04 |
canonical | ubuntu_linux | 7.10 |
canonical | ubuntu_linux | 8.04 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References