kernel: exit_notify: kill the wrong capable(CAP_KILL) check
Published Apr 22, 2009
4.4
MEDIUMCVSS 2.0
EPSS 1.26%
Description
The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.
Affected products
No data.
- ≤ 2.6.29
- 2.2.27
- 2.4.36
- 2.4.36.1
- 2.4.36.2
- 2.4.36.3
- 2.4.36.4
- 2.4.36.5
- 2.4.36.6
- 2.6
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.4
- 2.6.5
- 2.6.6
- 2.6.7
- 2.6.8
- 2.6.8.1
- 2.6.9
- 2.6.10
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.16.24
- 2.6.16.25
- 2.6.16.26
- 2.6.16.27
- 2.6.16.28
- 2.6.16.29
- 2.6.16.30
- 2.6.16.31
- 2.6.16.32
- 2.6.16.33
- 2.6.16.34
- 2.6.16.35
- 2.6.16.36
- 2.6.16.37
- 2.6.16.38
- 2.6.16.39
- 2.6.16.40
- 2.6.16.41
- 2.6.16.42
- 2.6.16.43
- 2.6.16.44
- 2.6.16.45
- 2.6.16.46
- 2.6.16.47
- 2.6.16.48
- 2.6.16.49
- 2.6.16.50
- 2.6.16.51
- 2.6.16.52
- 2.6.16.53
- 2.6.16.54
- 2.6.16.55
- 2.6.16.56
- 2.6.16.57
- 2.6.16.58
- 2.6.16.59
- 2.6.16.60
- 2.6.16.61
- 2.6.16.62
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
- 2.6.17.4
- 2.6.17.5
- 2.6.17.6
- 2.6.17.7
- 2.6.17.8
- 2.6.17.9
- 2.6.17.10
- 2.6.17.11
- 2.6.17.12
- 2.6.17.13
- 2.6.17.14
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18.1
- 2.6.18.2
- 2.6.18.3
- 2.6.18.4
- 2.6.18.5
- 2.6.18.6
- 2.6.18.7
- 2.6.18.8
- 2.6.19
- 2.6.19.1
- 2.6.19.2
- 2.6.19.3
- 2.6.19.4
- 2.6.19.5
- 2.6.19.6
- 2.6.19.7
- 2.6.20
- 2.6.20.1
- 2.6.20.2
- 2.6.20.3
- 2.6.20.4
- 2.6.20.5
- 2.6.20.6
- 2.6.20.7
- 2.6.20.8
- 2.6.20.9
- 2.6.20.10
- 2.6.20.11
- 2.6.20.12
- 2.6.20.13
- 2.6.20.14
- 2.6.20.15
- 2.6.20.16
- 2.6.20.17
- 2.6.20.18
- 2.6.20.19
- 2.6.20.20
- 2.6.20.21
- 2.6.21
- 2.6.21.1
- 2.6.21.2
- 2.6.21.3
- 2.6.21.4
- 2.6.21.5
- 2.6.21.6
- 2.6.21.7
- 2.6.22
- 2.6.22.1
- 2.6.22.2
- 2.6.22.3
- 2.6.22.4
- 2.6.22.5
- 2.6.22.6
- 2.6.22.7
- 2.6.22.8
- 2.6.22.9
- 2.6.22.10
- 2.6.22.11
- 2.6.22.12
- 2.6.22.13
- 2.6.22.14
- 2.6.22.15
- 2.6.22.16
- 2.6.22.17
- 2.6.22.18
- 2.6.22.19
- 2.6.22.20
- 2.6.22.21
- 2.6.22.22
- 2.6.22_rc1
- 2.6.22_rc7
- 2.6.23
- 2.6.23
- 2.6.23
- 2.6.23.1
- 2.6.23.2
- 2.6.23.3
- 2.6.23.4
- 2.6.23.5
- 2.6.23.6
- 2.6.23.7
- 2.6.23.8
- 2.6.23.9
- 2.6.23.10
- 2.6.23.11
- 2.6.23.12
- 2.6.23.13
- 2.6.23.14
- 2.6.23.15
- 2.6.23.16
- 2.6.23.17
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24.1
- 2.6.24.2
- 2.6.24.3
- 2.6.24.4
- 2.6.24.5
- 2.6.24.6
- 2.6.24.7
- 2.6.25
- 2.6.25
- 2.6.25.1
- 2.6.25.1
- 2.6.25.2
- 2.6.25.2
- 2.6.25.3
- 2.6.25.3
- 2.6.25.4
- 2.6.25.4
- 2.6.25.5
- 2.6.25.5
- 2.6.25.6
- 2.6.25.6
- 2.6.25.7
- 2.6.25.7
- 2.6.25.8
- 2.6.25.8
- 2.6.25.9
- 2.6.25.9
- 2.6.25.10
- 2.6.25.10
- 2.6.25.11
- 2.6.25.11
- 2.6.25.12
- 2.6.25.12
- 2.6.25.13
- 2.6.25.14
- 2.6.25.15
- 2.6.25.16
- 2.6.25.17
- 2.6.25.18
- 2.6.25.19
- 2.6.25.20
- 2.6.26
- 2.6.26
- 2.6.26.1
- 2.6.26.2
- 2.6.26.3
- 2.6.26.4
- 2.6.26.5
- 2.6.26.6
- 2.6.26.7
- 2.6.26.8
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27.1
- 2.6.27.2
- 2.6.27.3
- 2.6.27.4
- 2.6.27.5
- 2.6.27.6
- 2.6.27.7
- 2.6.27.8
- 2.6.27.9
- 2.6.27.10
- 2.6.27.11
- 2.6.27.12
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28.1
- 2.6.28.2
- 2.6.28.3
- 2.6.28.4
- 2.6.28.5
- 2.6.28.6
- 2.6.28.7
- 2.6.28.8
- 2.6.28.9
- 2.6.29
- 2.6.29
- 2.6.29
- 2.6.29
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-111.el5rt
Fixed · RHSA-2009:0451
Red Hat Enterprise Linux 3
kernel-0:2.4.21-63.EL
Fixed · RHSA-2009:1550
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.EL
Fixed · RHSA-2009:1024
Red Hat Enterprise Linux 4.7 Z Stream
kernel-0:2.6.9-78.0.24.EL
Fixed · RHSA-2009:1077
Red Hat Enterprise Linux 5
kernel-0:2.6.18-128.1.10.el5
Fixed · RHSA-2009:0473
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-111.el5rt | Fixed | RHSA-2009:0451 |
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-63.EL | Fixed | RHSA-2009:1550 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.EL | Fixed | RHSA-2009:1024 |
| Red Hat Enterprise Linux 4.7 Z Stream | kernel-0:2.6.9-78.0.24.EL | Fixed | RHSA-2009:1077 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-128.1.10.el5 | Fixed | RHSA-2009:0473 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (53)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=432870dab85a2f69dc417022646cb9a70acf7f94 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=linux-kernel&m=123560588713763&w=2 mailing-listx_refsource_MLIST
- http://patchwork.kernel.org/patch/16544/ x_refsource_CONFIRMPatch
- http://rhn.redhat.com/errata/RHSA-2009-0473.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/34917 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34981 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35011 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35015 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35120 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35121 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35160 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35185 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35226 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35324 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35387 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35390 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35394 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35656 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37471 third-party-advisoryx_refsource_SECUNIA
- http://wiki.rpath.com/Advisories:rPSA-2009-0084 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1787 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2009/dsa-1794 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2009/dsa-1800 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc1 x_refsource_CONFIRMVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:119 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:135 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2009/04/07/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/04/17/3 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2009-0451.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2009-1024.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2009-1077.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/503610/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/512019/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/34405 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022141 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-793-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-1337 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=493771 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1335 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1337
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10919 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11206 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8295 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2009-1550.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2009-1337
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.