NFS: Linux CAP-MKNOD Bypass

This signature detects attempts to exploit a known vulnerability against the Linux Kernel nfsd module. A successful attack can lead to a security bypass.

Extended Description

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Affected Products

Linux linux_kernel

References

CVE: CVE-2009-1072

Short Name
NFS:CAP-MKNOD-V4
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
NFS
Keywords
Bypass CAP-MKNOD CVE-2009-1072 Linux
Release Date
09/22/2022
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3650
False Positive
Unknown
Vendors

Suse

Opensuse

Linux

Debian

Vmware

Canonical

Found a potential security threat?