CVE-2008-3525

Linux kernel 2.6.26.3 - Privilege Escalation

Title source: llm

Description

The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMANSIPATE ioctl request, which allows local users to bypass intended capability restrictions.

References (33)

... and 13 more

Scores

EPSS 0.0006
EPSS Percentile 18.9%

Classification

CWE
CWE-264
Status draft

Affected Products (1)

linux/linux_kernel

Timeline

Published Sep 03, 2008
Tracked Since Feb 18, 2026