CVE-2009-1072

Linux kernel <2.6.28.9 - Privilege Escalation

Title source: llm

Description

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Scores

EPSS 0.0059
EPSS Percentile 68.9%

Classification

CWE
CWE-16
Status draft

Affected Products (20)

linux/linux_kernel < 2.6.28.9
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
suse/linux_enterprise_desktop
suse/linux_enterprise_server
debian/debian_linux
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
vmware/vcenter_server
vmware/virtualcenter
vmware/virtualcenter
... and 5 more

Timeline

Published Mar 25, 2009
Tracked Since Feb 18, 2026