CVE-2005-2555

Debian Linux - Access Control

Title source: rule

Description

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.

References (19)

Scores

EPSS 0.0009
EPSS Percentile 25.8%

Classification

CWE
CWE-264
Status draft

Affected Products (50)

debian/debian_linux
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Aug 16, 2005
Tracked Since Feb 18, 2026