AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-1940

MEDIUM · CVSS 4.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-04-25 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.6. See the original NVD description below for full technical details.

CVE
CVE-2008-1940
Severity
MEDIUM
CVSS
4.6
EPSS
0.32%

Original NVD Description

The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.