The net_ctl_permissions function in net/sysctl_net.c in...
Low severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Feb 21, 2023
Description
Published by the National Vulnerability Database
Dec 9, 2013
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Feb 21, 2023
The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.
References