NFS: Linux CAP-MKNOD Bypass
This signature detects attempts to exploit a known vulnerability against the Linux Kernel nfsd module. A successful attack can lead to a security bypass.
Extended Description
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
Affected Products
Linux linux_kernel
References
CVE: CVE-2009-1072
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
Suse
Opensuse
Linux
Debian
Vmware
Canonical