The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 2.6.38 |