udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
2009-04-17T14:30:00.563
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | udev_project | udev | < 141 | Yes |
Application | suse | linux_enterprise_debuginfo | 10 | Yes |
Application | suse | linux_enterprise_debuginfo | 11 | Yes |
Operating System | opensuse | opensuse | 10.3 | Yes |
Operating System | opensuse | opensuse | 11.0 | Yes |
Operating System | opensuse | opensuse | 11.1 | Yes |
Operating System | suse | linux_enterprise_desktop | 10 | Yes |
Operating System | suse | linux_enterprise_desktop | 11 | Yes |
Operating System | suse | linux_enterprise_server | 10 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | debian | debian_linux | 4.0 | Yes |
Operating System | debian | debian_linux | 5.0 | Yes |
Operating System | canonical | ubuntu_linux | 6.06 | Yes |
Operating System | canonical | ubuntu_linux | 7.10 | Yes |
Operating System | canonical | ubuntu_linux | 8.04 | Yes |
Operating System | canonical | ubuntu_linux | 8.10 | Yes |
Operating System | fedoraproject | fedora | 9 | Yes |
Operating System | fedoraproject | fedora | 10 | Yes |
Application | juniper | ctpview | < 7.1 | Yes |
Application | juniper | ctpview | 7.1 | Yes |
Application | juniper | ctpview | 7.1 | Yes |
Application | juniper | ctpview | 7.2 | Yes |