Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-7975

Опубликовано: 13 окт. 2014
Источник: debian
EPSS Низкий

Описание

The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed3.16.7-1package
linuxnot-affectedwheezypackage
linux-2.6removedpackage
linux-2.6not-affectedsqueezepackage

Примечания

  • http://thread.gmane.org/gmane.linux.kernel.stable/109312

  • Upstream commit: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0ef3a56b1c466629cd0bf482b09c7b0e5a085bb5 (v3.18-rc1)

EPSS

Процентиль: 12%
0.00041
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 10 лет назад

The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.

redhat
больше 10 лет назад

The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.

CVSS3: 5.5
nvd
больше 10 лет назад

The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.

CVSS3: 5.5
github
около 3 лет назад

The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.

oracle-oval
больше 10 лет назад

ELSA-2015-3012: Unbreakable Enterprise kernel security and bugfix update (IMPORTANT)

EPSS

Процентиль: 12%
0.00041
Низкий