VYPR
Unrated severityNVD Advisory· Published Mar 25, 2009· Updated Apr 23, 2026

CVE-2009-1072

CVE-2009-1072

Description

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Affected products

20
  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Range: <2.6.28.9
  • OpenSUSE/openSUSE3 versions
    cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_desktop:10:sp2:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:vcenter_server:4.0:-:*:*:*:*:*:*
  • cpe:2.3:a:vmware:virtualcenter:2.0.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vmware:virtualcenter:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:virtualcenter:2.5:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:server:2.0.0:*:*:*:*:*:*:*
  • VMware/Esx3 versions
    cpe:2.3:o:vmware:esx:3.0.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:vmware:esx:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esx:3.5:*:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:vma:4.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

28

News mentions

0

No linked articles in our index yet.