CVE-2008-2931

EUVD-2008-2924
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.22
debiandebian_linux
4.0
novellsuse_linux_enterprise_desktop
10.0:sp1
novellsuse_linux_enterprise_desktop
10.0:sp2
novellsuse_linux_enterprise_server
10.0:sp1
novellsuse_linux_enterprise_server
10.0:sp2
opensuseopensuse
10.3 ≤
𝑥
≤ 11.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
7.04
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
dapper
dne
feisty
dne
gutsy
dne
hardy
not-affected
linux-source-2.6.15
dapper
Fixed 2.6.15-52.71
released
feisty
dne
gutsy
dne
hardy
dne
linux-source-2.6.20
dapper
dne
feisty
Fixed 2.6.20-17.39
released
gutsy
dne
hardy
dne
linux-source-2.6.22
dapper
dne
feisty
dne
gutsy
not-affected
hardy
dne
References