A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-01-27T17:00:00

Updated: 2024-08-07T06:31:10.495Z

Reserved: 2009-10-05T00:00:00

Link: CVE-2009-3556

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-01-27T17:30:00.543

Modified: 2023-02-13T02:20:28.203

Link: CVE-2009-3556

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-01-19T00:00:00Z

Links: CVE-2009-3556 - Bugzilla