{"api_version":"1","generated_at":"2026-07-23T09:20:06+00:00","cve":"CVE-2009-3725","urls":{"html":"https://cve.report/CVE-2009-3725","api":"https://cve.report/api/cve/CVE-2009-3725.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3725","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3725"},"summary":{"title":"CVE-2009-3725","description":"The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.","state":"PUBLISHED","assigner":"redhat","published_at":"2009-11-06 15:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://marc.info/?l=oss-security&m=125716192622235&w=2","name":"http://marc.info/?l=oss-security&m=125716192622235&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"'Re: [oss-security] CVE request: kernel: connector security bypass' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://patchwork.kernel.org/patch/51383/","name":"http://patchwork.kernel.org/patch/51383/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"[6/8] dst/connector: Disallow unpliviged users to configure dst - Patchwork","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://patchwork.kernel.org/patch/51382/","name":"http://patchwork.kernel.org/patch/51382/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"[5/8] dm/connector: Only process connector packages from privileged processes - Patchwork","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://patchwork.kernel.org/patch/51387/","name":"http://patchwork.kernel.org/patch/51387/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"[7/8] pohmelfs/connector: Disallow unpliviged users to configure pohmelfs - Patchwork","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://patchwork.kernel.org/patch/51384/","name":"http://patchwork.kernel.org/patch/51384/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"[8/8] uvesafb/connector: Disallow unpliviged users to send netlink packets - Patchwork","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38905","name":"http://secunia.com/advisories/38905","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for linux-2.6 - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xorl.wordpress.com/2009/10/31/linux-kernel-multiple-capabilities-missing-checks/","name":"http://xorl.wordpress.com/2009/10/31/linux-kernel-multiple-capabilities-missing-checks/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"Linux kernel Multiple Capabilities Missing Checks « xorl %eax, %eax","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5","name":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/37113","name":"http://secunia.com/advisories/37113","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Linux Kernel connector Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-864-1","name":"http://www.ubuntu.com/usn/usn-864-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-864-1: Linux kernel vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=linux-kernel&m=125449888416314&w=2","name":"http://marc.info/?l=linux-kernel&m=125449888416314&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"'Re: [PATCH 0/8] SECURITY ISSUE with connector' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36834","name":"http://www.securityfocus.com/bid/36834","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Linux Kernel Subsystem Connector Missing Capability Check Security Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=oss-security&m=125715484511380&w=2","name":"http://marc.info/?l=oss-security&m=125715484511380&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"'[oss-security] CVE request: kernel: connector security bypass' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3725","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3725","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"6.06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"8.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"8.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"9.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"9.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-3725","organization":"Red Hat","lastmodified":"2009-11-09","contributor":"Tomas Hoger","statementText":"Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 or Red Hat Enterprise MRG, as they do not include the upstream change introducing this flaw.","cve_year":"2009","cve_id":"3725","crc32":"a966b56e"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:38:30.225Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5"},{"name":"38905","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38905"},{"name":"[linux-kernel] 20091002 Re: [PATCH 0/8] SECURITY ISSUE with connector","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=linux-kernel&m=125449888416314&w=2"},{"name":"USN-864-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-864-1"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://xorl.wordpress.com/2009/10/31/linux-kernel-multiple-capabilities-missing-checks/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://patchwork.kernel.org/patch/51383/"},{"name":"37113","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37113"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://patchwork.kernel.org/patch/51387/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://patchwork.kernel.org/patch/51382/"},{"name":"[oss-security] 20091102 Re: CVE request: kernel: connector security bypass","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=oss-security&m=125716192622235&w=2"},{"name":"[oss-security] 20091102 CVE request: kernel: connector security bypass","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=oss-security&m=125715484511380&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://patchwork.kernel.org/patch/51384/"},{"name":"36834","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36834"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-10-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-03-02T10:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5"},{"name":"38905","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38905"},{"name":"[linux-kernel] 20091002 Re: [PATCH 0/8] SECURITY ISSUE with connector","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=linux-kernel&m=125449888416314&w=2"},{"name":"USN-864-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-864-1"},{"tags":["x_refsource_MISC"],"url":"http://xorl.wordpress.com/2009/10/31/linux-kernel-multiple-capabilities-missing-checks/"},{"tags":["x_refsource_CONFIRM"],"url":"http://patchwork.kernel.org/patch/51383/"},{"name":"37113","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37113"},{"tags":["x_refsource_CONFIRM"],"url":"http://patchwork.kernel.org/patch/51387/"},{"tags":["x_refsource_CONFIRM"],"url":"http://patchwork.kernel.org/patch/51382/"},{"name":"[oss-security] 20091102 Re: CVE request: kernel: connector security bypass","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=oss-security&m=125716192622235&w=2"},{"name":"[oss-security] 20091102 CVE request: kernel: connector security bypass","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=oss-security&m=125715484511380&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://patchwork.kernel.org/patch/51384/"},{"name":"36834","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36834"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2009-3725","datePublished":"2009-11-06T15:00:00.000Z","dateReserved":"2009-10-16T00:00:00.000Z","dateUpdated":"2024-08-07T06:38:30.225Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-11-06 15:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"2.6.31.5","matchCriteriaId":"61EA5B82-D1EB-4D3D-B82C-3A6CD1FB4938"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*","matchCriteriaId":"5C18C3CD-969B-4AA3-AE3A-BA4A188F8BFF"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*","matchCriteriaId":"C91D2DBF-6DA7-4BA2-9F29-8BD2725A4701"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*","matchCriteriaId":"4747CC68-FAF4-482F-929A-9DA6C24CB663"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*","matchCriteriaId":"A5D026D0-EF78-438D-BEDD-FC8571F3ACEB"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*","matchCriteriaId":"A2BCB73E-27BB-4878-AD9C-90C4F20C25A0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3725","Ordinal":"1","Title":"CVE-2009-3725","CVE":"CVE-2009-3725","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3725","Ordinal":"1","NoteData":"The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.","Type":"Description","Title":"CVE-2009-3725"},{"CveYear":"2009","CveId":"3725","Ordinal":"2","NoteData":"2009-11-06","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3725","Ordinal":"3","NoteData":"2010-03-02","Type":"Other","Title":"Modified"}]}}}