---
title: "CVE-2009-3725\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-3725?format=md
keywords: index, follow
---

# CVE-2009-3725

Publication date 6 November 2009

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The connector layer in the Linux kernel before 2.6.31.5 does not require
the CAP\_SYS\_ADMIN capability for certain interaction with the (1) uvesafb,
(2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to
bypass intended access restrictions and gain privileges via calls to
functions in these subsystems.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux | 9.10 karmic | Fixed 2.6.31-16.52 |
| 9.04 jaunty | Fixed 2.6.28-17.58 |
| 8.10 intrepid | Fixed 2.6.27-16.44 |
| 8.04 LTS hardy | Fixed 2.6.24-26.64 |
| 6.06 LTS dapper | Not in release |
| linux-source-2.6.15 | 9.10 karmic | Not in release |
| 9.04 jaunty | Not in release |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3725)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-3725)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-3725)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-3725)

### Related Ubuntu Security Notices (USN)

+ [USN-864-1](https://usn.ubuntu.com/USN-864-1)
+ Linux kernel vulnerabilities
+ 5 December 2009

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-3725>
