PT-2010-1294 · Linux+1 · Linux Kernel+1
Bryn M. Reeves
·
Published
2010-01-19
·
Updated
2023-02-13
·
CVE-2009-3556
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Linux (RHEL) 5 with Linux kernel 2.6.18
Description
The issue concerns a Red Hat configuration step for the qla2xxx driver in the Linux kernel when N Port ID Virtualization (NPIV) hardware is used. This configuration sets world-writable permissions for certain files under /sys/class/scsi host/, specifically the
vport create and vport delete files. As a result, local users can modify these files to make arbitrary changes to SCSI host attributes.Recommendations
For Red Hat Enterprise Linux (RHEL) 5 with Linux kernel 2.6.18, consider restricting access to the
vport create and vport delete files under /sys/class/scsi host/ to prevent local users from making unauthorized changes to SCSI host attributes.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat