← Back to CVE List

CVE-2014-9645

Published: 2017-03-12T06:59Z
Last Modified: 2024-11-21T02:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt