Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1019

Опубликовано: 24 фев. 2011
Источник: redhat
CVSS2: 1.5
EPSS Низкий

Описание

The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.

Отчет

This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not backport the upstream commit a8f80e8f that introduced this flaw. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0498.html and https://rhn.redhat.com/errata/RHSA-2011-0500.html.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=680360kernel: CAP_SYS_MODULE bypass via CAP_NET_ADMIN

EPSS

Процентиль: 18%
0.00057
Низкий

1.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.

nvd
больше 12 лет назад

The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.

debian
больше 12 лет назад

The dev_load function in net/core/dev.c in the Linux kernel before 2.6 ...

github
около 3 лет назад

The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.

oracle-oval
около 14 лет назад

ELSA-2011-2015: Oracle Linux 6 Unbreakable Enterprise kernel security fix update (IMPORTANT)

EPSS

Процентиль: 18%
0.00057
Низкий

1.5 Low

CVSS2