Back

MEDIUM

kernel: open() call allows setgid bit when user is not in new file's group

Published Sep 29, 2008

Description

fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 29, 2008
Updated Aug 7, 2024
Reserved Sep 24, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 2, 2007