Red Hat Bugzilla – Bug 126718
CAN-2004-0497 inode_change_ok missing checks allows GID changes (ipf)
Last modified: 2013-03-06 00:57:07 EST
An audit by SUSE found a missing "must be owner of the file" check in inode_change_ok(). In the 2.6 kernel this allows a local user to be able to change the groupid of any object (except those setgid) by using chown. In the 2.4 kernel this is exploitable only via a kernel nfsd export where the server will grant requests to change GID when it shouldn't. SUSE suggested an embargo date of Jul14 1600MEST but this has been adjusted to Jun29 1600MEST.
Embargo moved to Jul02 1000MEST
Removing embargo
An errata has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2004-327.html