Back

LOW

kernel: ima: fix add LSM rule bug

Published Jun 21, 2012

Description

The ima_lsm_rule_init function in security/integrity/ima/ima_policy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunistic circumstances by leveraging an administrator's addition of an IMA rule for LSM.

Affected products

Remediation

Red Hat statement

The Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, and Red Hat Enterprise MRG are not affected by this issue. A future kernel update in Red Hat Enterprise Linux 6 may address this flaw.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 21, 2012
Updated Aug 6, 2024
Reserved Dec 7, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jan 4, 2011