Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8374

Опубликовано: 28 дек. 2015
Источник: debian
EPSS Низкий

Описание

fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.2.6-2package
linuxfixed3.16.7-ckt20-1+deb8u1jessiepackage
linuxfixed3.2.78-1wheezypackage
linux-2.6removedpackage
linux-2.6no-dsasqueezepackage

Примечания

  • https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0305cd5f7fca85dae392b9ba85b116896eb7c1c7 (v4.4-rc1)

  • https://www.openwall.com/lists/oss-security/2015/11/27/2

  • CVE assignment for the vulnerability with the impact of "User B now

  • gets to see the 1000 bytes that user A truncated from its file before

  • it made its file world readable"

EPSS

Процентиль: 8%
0.00033
Низкий

Связанные уязвимости

CVSS3: 4
ubuntu
больше 9 лет назад

fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

redhat
больше 9 лет назад

fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

CVSS3: 4
nvd
больше 9 лет назад

fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

CVSS3: 4
github
около 3 лет назад

fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

oracle-oval
почти 9 лет назад

ELSA-2016-3618: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 8%
0.00033
Низкий