Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38f7-vv5r-859m

Опубликовано: 26 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

EPSS

Процентиль: 100%
0.91742
Критический

7.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CVSS3: 7.8
redhat
больше 2 лет назад

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CVSS3: 7.8
nvd
больше 2 лет назад

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CVSS3: 7.8
debian
больше 2 лет назад

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overl ...

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость файловой системы overlayfs ядра операционной системы Ubuntu, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 100%
0.91742
Критический

7.8 High

CVSS3

Дефекты

CWE-863