The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.
References
Configurations
Information
Published : 2009-09-18 03:30
Updated : 2017-09-28 18:34
NVD link : CVE-2009-1883
Mitre link : CVE-2009-1883
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
linux
- linux_kernel