Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9717

Опубликовано: 07 окт. 2014
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.

It was found that unsharing a mount namespace could allow a user to see data beneath their restricted namespace.

Отчет

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=1226751kernel: unsharing MNT_LOCKED mount can expose files beneath the mount.

EPSS

Процентиль: 12%
0.00041
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 10 лет назад

fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.

CVSS3: 6.1
nvd
почти 10 лет назад

fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.

CVSS3: 6.1
debian
почти 10 лет назад

fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH u ...

CVSS3: 6.1
github
больше 3 лет назад

fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.

suse-cvrf
больше 9 лет назад

Security update for the Linux Kernel

EPSS

Процентиль: 12%
0.00041
Низкий

2.6 Low

CVSS2