Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 102805 - IPsec policy bypass (CAN-2005-2555)
Summary: IPsec policy bypass (CAN-2005-2555)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.kernel.org/git/?p=linux/ke...
Whiteboard: [linux < 2.6.12.6]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-08-17 02:58 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2009-05-03 15:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-17 02:58:15 UTC
Linux kernel 2.6.x does not properly restrict socket policy access to 
users with the CAP_NET_ADMIN capability, which could allow local users 
to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) 
ipv6/ipv6_sockglue.c.
Comment 1 Tim Yamin (RETIRED) gentoo-dev 2005-08-19 11:41:53 UTC
Not in 2.6.12.5 for some reason (and public for a few weeks); opening bug.
Comment 2 Daniel Drake (RETIRED) gentoo-dev 2005-08-29 17:52:25 UTC
Fixed in 2.6.12.6
Fixed in gentoo-sources-2.6.12-r10
Fixed in genpatches-2.6.12-14
Comment 3 Tim Yamin (RETIRED) gentoo-dev 2005-12-24 04:34:26 UTC
All fixed, closing bug.