CVE-2010-0007
Summary
| CVE | CVE-2010-0007 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-01-19 16:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.0 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.13.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.13.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.13.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.13.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.13.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.20 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.21 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.22 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.23 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.24 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.25 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.26 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.27 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.28 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.29 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.30 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.31 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.24 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.32 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.32.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.32.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.32.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.32.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.8.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.9 | All | All | All |
| Operating System | Linux | Linux Kernel | All | rc3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - Re: CVE Request: kernel ebtables perm check | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| SUSE update for kernel - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-2005-1 linux-2.6.24 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| oss-security - CVE Request: kernel ebtables perm check | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| VMSA-2011-0003 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| Red Hat update for kernel-rt - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug 555238 – CVE-2010-0007 kernel: netfilter: ebtables: enforce CAP_NET_ADMIN | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Fedora update for kernel - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| VMware ESX Server Multiple Kernel Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| Debian -- Security Information -- DSA-1996-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Linux Kernel ebtables Security Bypass - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian update for linux-2.6 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Linux Kernel 'ebtables' Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SUSE update for kernel - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] Fedora 11 Update: kernel-2.6.30.10-105.2.4.fc11 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-03-17 | Vincent Danen | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/CVE-2010-0007. This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 3, as it did not include support for ebtables. This issue was addressed in Red Hat Enterprise Linux 4 and 5 via https://rhn.redhat.com/errata/RHSA-2010-0146.html and https://rhn.redhat.com/errata/RHSA-2010-0147.html respectively. A futur e update in Red Hat Enterprise MRG may address this flaw. |
There are currently no legacy QID mappings associated with this CVE.