udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libvolume_idUpgrade udevUpgrade libvolume_id-devel | Dec 1, 2016 | Apr 17, 2009 |
| Gentoo Linux | — | Upgrade sys-fs/udev. | Oct 30, 2017 | Apr 17, 2009 |
| Oracle_linux | — | Upgrade udevUpgrade libvolume_idUpgrade libvolume_id-devel | Oct 16, 2024 | Apr 17, 2009 |
| Suse | — | Upgrade libudev-develUpgrade libvolume_id1Upgrade libvolume_idUpgrade udevUpgrade libvolume_id-develUpgrade libudev0 | Feb 17, 2015 | Apr 17, 2009 |
| Ubuntu | — | Upgrade udev | Nov 8, 2024 | Apr 17, 2009 |
| Vmsa 2009 0009 Service Console Package Udev | — | Upgrade VMware ESX 4.0 to build number 175625 | Sep 2, 2010 | Apr 17, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub