CVE-2009-1072
Linux kernel <2.6.28.9 - Privilege Escalation
Title source: llmDescription
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
References (29)
... and 9 more
Scores
EPSS
0.0059
EPSS Percentile
68.9%
Classification
CWE
CWE-16
Status
draft
Affected Products (20)
linux/linux_kernel
< 2.6.28.9
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
suse/linux_enterprise_desktop
suse/linux_enterprise_server
debian/debian_linux
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
vmware/vcenter_server
vmware/virtualcenter
vmware/virtualcenter
... and 5 more
Timeline
Published
Mar 25, 2009
Tracked Since
Feb 18, 2026