Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6pr-c5vr-9466

Опубликовано: 03 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

EPSS

Процентиль: 8%
0.0003
Низкий

7.8 High

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

CVSS3: 6.7
redhat
больше 4 лет назад

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

CVSS3: 7.8
nvd
почти 4 года назад

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

CVSS3: 7.8
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 4 года назад

An unauthorized access to the execution of the setuid file with capabi ...

EPSS

Процентиль: 8%
0.0003
Низкий

7.8 High

CVSS3

Дефекты

CWE-281