CVE-2009-0675

Linux kernel <2.6.28.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver statistics, related to an "inverted logic" issue.

References (27)

Core 27
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33938
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0326.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0360.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11529
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33758
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-751-1
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507985/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34502
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37471
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1749
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1794
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35011
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2009/02/20/2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34981
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34394
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8685
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1787
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:071
Various Sources mailing-list x_refsource_mlist
http://lists.openwall.net/netdev/2009/01/28/90
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34680
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3316
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=486534
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35394

Scores

EPSS 0.0040
EPSS Percentile 33.1%

Details

CWE
CWE-264
Status published
Products (50)
linux/linux_kernel 2.6
linux/linux_kernel 2.6.0
linux/linux_kernel 2.6.1
linux/linux_kernel 2.6.2
linux/linux_kernel 2.6.3
linux/linux_kernel 2.6.4
linux/linux_kernel 2.6.5
linux/linux_kernel 2.6.6
linux/linux_kernel 2.6.7
linux/linux_kernel 2.6.8
... and 40 more
Published Feb 22, 2009
Tracked Since Feb 18, 2026