CVE-2009-1630
MEDIUM severity · CVSS 4.4 · CWE-264
4.4CVSS MEDIUM
Summary
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
Impact & exploitability
Attack vectorLocal
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)0%
AV:L/AC:M/Au:N/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://bugzilla.linux-nfs.org/show_bug.cgi?id=131 ↗
Additional information
- NVD record
- http://bugzilla.linux-nfs.org/show_bug.cgi?id=131Patch
- http://linux-nfs.org/pipermail/nfsv4/2006-November/005313.html
- http://linux-nfs.org/pipermail/nfsv4/2006-November/005323.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.htmlAdvisory
- http://secunia.com/advisories/35106
- http://secunia.com/advisories/35298
- http://article.gmane.org/gmane.linux.nfs/26592Exploit