Hide Forgot
Description of problem: commit dce766af541f6605fa9889892c0280bab31c66ab Author: Florian Westphal <fwestphal> Date: Fri Jan 8 17:31:24 2010 +0100 netfilter: ebtables: enforce CAP_NET_ADMIN normal users are currently allowed to set/modify ebtables rules. Restrict it to processes with CAP_NET_ADMIN. Note that this cannot be reproduced with unmodified ebtables binary because it uses SOCK_RAW. Signed-off-by: Florian Westphal <fwestphal> Cc: stable Signed-off-by: Patrick McHardy <kaber> Upstream commit: http://git.kernel.org/linus/dce766af541f6605fa9889892c0280bab31c66ab
Note: impact=low/AC:H because ebtables binary uses SOCK_RAW which you need root privileges in the first place. rhel-3 doesn't have support for ebtables and the impact is low, so I didn't file a bug for it.
kernel-2.6.30.10-105.2.4.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/kernel-2.6.30.10-105.2.4.fc11
kernel-2.6.30.10-105.2.4.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0147 https://rhn.redhat.com/errata/RHSA-2010-0147.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Via RHSA-2010:0146 https://rhn.redhat.com/errata/RHSA-2010-0146.html
This issue has been addressed in following products: MRG for RHEL-5 Via RHSA-2010:0161 https://rhn.redhat.com/errata/RHSA-2010-0161.html