Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2854

Опубликовано: 02 мая 2016
Источник: debian
EPSS Низкий

Описание

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed3.18-1~exp1package
linuxignoredjessiepackage
linuxnot-affectedwheezypackage

Примечания

  • http://www.halfdog.net/Security/2016/AufsPrivilegeEscalationInUserNamespaces/

  • https://sourceforge.net/p/aufs/mailman/message/34864744/

  • This depends on a user namespace creator being able to mount aufs.

  • jessie: Unprivileged users are not allowed to create user namespaces by default; aufs is not allowed to be mounted from a new user namespace by default.

  • wheezy: User namespaces are non-functional.

EPSS

Процентиль: 58%
0.0095
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 10 лет назад

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

redhat
больше 10 лет назад

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

CVSS3: 7.8
nvd
больше 10 лет назад

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

CVSS3: 7.8
github
больше 4 лет назад

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

EPSS

Процентиль: 58%
0.0095
Низкий