Unrated severityNVD Advisory· Published Sep 14, 2007· Updated Jun 16, 2026
CVE-2007-3740
CVE-2007-3740
Description
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 30 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <=2.6.21.7
- cpe:2.3:o:linux:linux_kernel:2.2.27:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.4.36:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.4.36.1:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.4.36.2:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.4.36.3:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.4.36.4:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.4.36.5:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.4.36.6:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.18:rc7:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19.4:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19.5:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19.6:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19.7:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.20.16:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.20.17:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.20.18:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.20.19:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.20.20:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.20.21:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.21.5:*:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.21.6:*:*:*:*:*:*:*
- (no CPE)range: <2.6.22
Patches
Vulnerability mechanics
References
23- secunia.com/advisories/26760nvdVendor Advisory
- secunia.com/advisories/26955nvdVendor Advisory
- secunia.com/advisories/26978nvdVendor Advisory
- secunia.com/advisories/27436nvdVendor Advisory
- secunia.com/advisories/27747nvdVendor Advisory
- secunia.com/advisories/27912nvdVendor Advisory
- secunia.com/advisories/28806nvdVendor Advisory
- secunia.com/advisories/29058nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.htmlnvd
- support.avaya.com/elmodocs2/security/ASA-2007-474.htmnvd
- www.debian.org/security/2007/dsa-1378nvd
- www.debian.org/security/2008/dsa-1504nvd
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2007-0705.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-0939.htmlnvd
- www.securityfocus.com/bid/25672nvd
- www.ubuntu.com/usn/usn-518-1nvd
- bugzilla.redhat.com/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36593nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9953nvd
News mentions
0No linked articles in our index yet.