| Vigil@nce team describes computer vulnerabilities impacting your systems, and offers solutions to correct them. |
|
 |
|
|
|
vulnerability alert CVE-2010-0299
Linux kernel: incorrect permissions on devtmpfs
Synthesis of the vulnerability
| On a 2.6.32.x kernel, a local attacker can access to devtmpfs. |
Severity: 2/4.
Creation date: 01/02/2010.
|
Description of the vulnerability
The devtmpfs filesystem was added in the kernel 2.6.32. It is used to create device nodes, before mounting the / root, and before mounting it to /dev.
A vulnerability, related to default access rights to devtmpfs, was announced. Technical details are unknown.
On a 2.6.32.x kernel, a local attacker can thus for example directly access to some restricted devices. |
Complete Vigil@nce bulletin
Characteristics
Title: Linux kernel: incorrect permissions on devtmpfs.
Keywords: Linux devtmpfs incorrect kernel permissions.
Identifiers: BID-38437, CVE-2010-0299, MDVSA-2010:030, SUSE-SA:2010:010, VIGILANCE-VUL-9396.
|
Information sources
Solutions for this vulnerability
Computer vulnerabilities tracking service
The Vigil@nce computer vulnerability tracking service alerts your teams of vulnerabilities or threats impacting your information system.
The Vigil@nce vulnerability database contains several thousand vulnerabilities.
This bulletin is published by the Vigil@nce team, which tracks computer vulnerabilities impacting systems and applications.
Computer applications vulnerability
|