CVE-2009-3725
Summary
| CVE | CVE-2009-3725 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-11-06 15:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 9.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 9.10 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'Re: [oss-security] CVE request: kernel: connector security bypass' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| [6/8] dst/connector: Disallow unpliviged users to configure dst - Patchwork | af854a3a-2127-422b-91ae-364da2661108 | patchwork.kernel.org | Patch, Vendor Advisory |
| [5/8] dm/connector: Only process connector packages from privileged processes - Patchwork | af854a3a-2127-422b-91ae-364da2661108 | patchwork.kernel.org | Patch, Vendor Advisory |
| [7/8] pohmelfs/connector: Disallow unpliviged users to configure pohmelfs - Patchwork | af854a3a-2127-422b-91ae-364da2661108 | patchwork.kernel.org | Patch, Vendor Advisory |
| [8/8] uvesafb/connector: Disallow unpliviged users to send netlink packets - Patchwork | af854a3a-2127-422b-91ae-364da2661108 | patchwork.kernel.org | Patch, Vendor Advisory |
| Debian update for linux-2.6 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Linux kernel Multiple Capabilities Missing Checks « xorl %eax, %eax | af854a3a-2127-422b-91ae-364da2661108 | xorl.wordpress.com | Exploit, Third Party Advisory |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | Vendor Advisory |
| Linux Kernel connector Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| USN-864-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| 'Re: [PATCH 0/8] SECURITY ISSUE with connector' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| Linux Kernel Subsystem Connector Missing Capability Check Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Third Party Advisory |
| '[oss-security] CVE request: kernel: connector security bypass' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-11-09 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 or Red Hat Enterprise MRG, as they do not include the upstream change introducing this flaw. |
There are currently no legacy QID mappings associated with this CVE.