Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-16120

Опубликовано: 10 фев. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 5.1

Описание

Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by the user, like a removable device. This was introduced in kernel version 4.19 by commit d1d04ef ("ovl: stack file ops"). This was fixed in kernel version 5.8 by commits 56230d9 ("ovl: verify permissions in ovl_path_open()"), 48bd024 ("ovl: switch to mounter creds in readdir") and 05acefb ("ovl: check permission to open real file"). Additionally, commits 130fdbc ("ovl: pass correct flags for opening real directory") and 292f902 ("ovl: call secutiry hook in ovl_real_ioctl()") in kernel 5.8 might also be desired or necessary. These additional commits introduced a regression in overlay mounts within user namespaces which prevented access to files with ownership outside of the...

РелизСтатусПримечание
bionic

released

4.15.0-121.123
devel

not-affected

6.14.0-15.15
esm-infra-legacy/trusty

ignored

ESM criteria, was needed
esm-infra/bionic

not-affected

4.15.0-121.123
esm-infra/focal

not-affected

5.4.0-51.56
esm-infra/xenial

ignored

, was needed
focal

released

5.4.0-51.56
groovy

not-affected

5.8.0-16.17
hirsute

not-affected

5.8.0-36.40+21.04.1
jammy

not-affected

5.13.0-19.19

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

kinetic

not-affected

lunar

not-affected

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.19.0-1007.7~22.04.1
kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1086.91
devel

not-affected

6.14.0-1005.5
esm-infra-legacy/trusty

ignored

ESM criteria, was needed
esm-infra/bionic

not-affected

4.15.0-1086.91
esm-infra/focal

not-affected

5.4.0-1028.29
esm-infra/xenial

ignored

, was needed
focal

released

5.4.0-1028.29
groovy

not-affected

5.8.0-1004.4
hirsute

not-affected

5.8.0-1018.20+21.04.1
jammy

not-affected

5.13.0-1005.6

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-aws-5.3, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1015.19~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1015.19~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-aws-5.4, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-1028.29~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1028.29~18.04.1
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-1008.8~22.04.1
mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1009.9~22.04.2
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-1051.56+fips1
fips-updates/bionic

released

4.15.0-2030.31
fips-updates/focal

released

5.4.0-1069.73+fips2
fips-updates/jammy

not-affected

5.15.0-1052.57+fips1
fips-updates/xenial

DNE

fips/bionic

needed

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

4.15.0-1085.90~16.04.1
focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

6.14.0-1004.4
esm-infra-legacy/trusty

not-affected

4.15.0-1098.109~14.04.1
esm-infra/bionic

ignored

superseded by linux-azure-5.3, was needs-triage
esm-infra/focal

not-affected

5.4.0-1031.32
esm-infra/xenial

not-affected

4.15.0-1098.109~16.04.1
focal

released

5.4.0-1031.32
groovy

not-affected

5.8.0-1004.4
hirsute

not-affected

5.8.0-1016.17+21.04.1
jammy

not-affected

5.13.0-1006.7

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1099.110
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1099.110
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1007.8~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1007.8~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-azure-5.4, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-1031.32~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1031.32~18.04.1
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-1008.8~24.04.1
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-1007.7~22.04.1
mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1008.8~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-azure-5.3, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-azure-fde-5.15
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-azure-fde-5.15]
jammy

not-affected

5.15.0-1019.24.1
noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1019.24~20.04.1.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1019.24~20.04.1.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-1053.61+fips1
fips-updates/bionic

released

4.15.0-2012.14
fips-updates/focal

released

5.4.0-1073.76+fips1
fips-updates/jammy

not-affected

5.15.0-1058.66+fips1
fips-updates/xenial

DNE

fips/bionic

needed

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.8.0-1013.14
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

bluefield/jammy

not-affected

5.15.0-1011.13
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1011.14
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1011.14
jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1005.8
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-73.80+fips1
fips-updates/bionic

released

4.15.0-1044.50
fips-updates/focal

not-affected

5.4.0-1026.30
fips-updates/jammy

not-affected

5.15.0-92.102+fips1
fips-updates/xenial

needed

fips/bionic

needed

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

6.14.0-1006.6
esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-gcp-5.3, was needs-triage
esm-infra/focal

not-affected

5.4.0-1028.29
esm-infra/xenial

not-affected

4.15.0-1086.98~16.04.1
focal

released

5.4.0-1028.29
groovy

not-affected

5.8.0-1002.2
hirsute

not-affected

5.8.0-1015.15+21.04.1
jammy

not-affected

5.13.0-1005.6

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1086.98
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1086.98
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1006.9~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1006.9~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.19.0-1020.22~22.04.2
kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-gcp-5.4, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-1028.29~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1028.29~18.04.1
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-1006.6~24.04.2
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-1010.10~22.04.3
mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1010.11~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

end of kernel support, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-1048.56+fips1
fips-updates/bionic

not-affected

4.15.0-2013.14
fips-updates/focal

released

5.4.0-1067.71~20.04.1
fips-updates/jammy

not-affected

5.15.0-1048.56+fips1
fips-updates/xenial

DNE

fips/bionic

needed

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

end of kernel support
focal

ignored

end of kernel support
jammy

not-affected

5.15.0-1002.2
noble

not-affected

6.8.0-1003.5
oracular

DNE

plucky

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1072.76
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1072.76
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.0.0-1049.50
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.3.0-1038.40
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-1027.28~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1027.28~18.04.1
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1008.9
focal

not-affected

5.4.0-1008.9
groovy

DNE

hirsute

DNE

jammy

not-affected

5.15.0-1001.2
mantic

DNE

noble

not-affected

6.8.0-1001.3

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

not-affected

5.15.0-1003.5~20.04.2
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1003.5~20.04.2
jammy

DNE

kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-1003.3
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1003.3
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.3.0-68.63
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.3.0-68.63
esm-infra/focal

DNE

esm-infra/xenial

not-affected

4.15.0-120.122~16.04.1
focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-33.34~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-33.34~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-51.56~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-51.56~18.04.1
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.8.0-23.24~20.04.1
focal

not-affected

5.8.0-23.24~20.04.1
groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-19.19~24.04.1
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-14.14~22.04.1
lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-38.38~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-hwe-5.4, was needs-triage
esm-infra/focal

DNE

esm-infra/xenial

ignored

superseded by linux-hwe, was needs-triage
focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1004.5
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1004.5
jammy

not-affected

5.15.0-1002.2
noble

not-affected

6.5.0-1009.9
oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

not-affected

5.15.0-1034.37~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1034.37~20.04.1
jammy

DNE

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-1010.11~18.04.2
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1010.11~18.04.2
esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.8.0-1001.6
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

ignored

superseded by Ubuntu Pro ppa version
noble

DNE

oracular

DNE

plucky

DNE

realtime/jammy

not-affected

5.15.0-1021.26
trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-1004.6
noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1003.5~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1003.5~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1001.3
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1001.3
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1077.79
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1077.79
esm-infra/focal

not-affected

5.4.0-1026.27
esm-infra/xenial

ignored

, was needed
focal

released

5.4.0-1026.27
groovy

not-affected

5.8.0-1001.1
hirsute

not-affected

5.8.0-1010.11+21.04.1
jammy

not-affected

5.13.0-1004.4

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

not-affected

6.5.0-1003.6

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-22.22
noble

not-affected

6.5.0-9.9.1
oracular

not-affected

6.8.0-31.31.1
plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-33.34~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-33.34~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-1011.12~24.04.1
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-lowlatency-hwe-6.5, was needs-triage
lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-14.14.1~22.04.1
lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-38.38.1~22.04.2
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

mantic

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

ignored

ESM criteria, was needed
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-1005.5
kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.2.0-1003.3~22.04.1
lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-1004.4
mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1008.8~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.8.0-1009.9.1
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-1013.13
noble

not-affected

6.8.0-1003.3
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

not-affected

5.15.0-1009.9~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1009.9~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-1001.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1099.109
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1099.109
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.10.0-1008.9
focal

not-affected

5.10.0-1008.9
groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.6.0-1031.32
focal

released

5.6.0-1031.32
groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-1007.7
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.14.0-1004.4
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-1003.3
lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.8.0-1003.3
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.0.0-1069.75
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1057.62
devel

not-affected

6.14.0-1005.5
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1057.62
esm-infra/focal

not-affected

5.4.0-1028.29
esm-infra/xenial

not-affected

4.15.0-1056.61~16.04.1
focal

released

5.4.0-1028.29
groovy

not-affected

5.8.0-1001.1
hirsute

not-affected

5.8.0-1014.14+21.04.1
jammy

not-affected

5.13.0-1008.10

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-oracle-5.3, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1007.9~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1007.9~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-oracle-5.4, was needs-triage
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-1028.29~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1028.29~18.04.1
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1006.6~22.04.3
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

6.14.0-1005.5
esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1021.24
focal

released

5.4.0-1021.24
groovy

not-affected

5.8.0-1002.5
hirsute

not-affected

5.8.0-1008.11+21.04.1
jammy

not-affected

5.13.0-1008.9
kinetic

not-affected

5.15.0-1005.5
lunar

not-affected

5.19.0-1004.10

Показывать по

РелизСтатусПримечание
bionic

released

5.4.0-1021.24~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1021.24~18.04.1
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

ignored

superseded by Ubuntu Pro ppa version
oracular

DNE

plucky

DNE

realtime/noble

not-affected

6.7.0-2001.1
trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1073.78
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

replaced by linux-raspi
focal

ignored

end of standard support, was ignored [replaced by linux-raspi, was needs-triage]
groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

released

5.3.0-1035.37
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

6.14.0-1002.2
esm-infra/focal

DNE

focal

DNE

jammy

ignored

superseded by Ubuntu Pro ppa version
noble

not-affected

6.8.1-1015.16
oracular

not-affected

6.11.0-1001.1
plucky

not-affected

6.11.0-1001.1
realtime/jammy

not-affected

5.15.0-1006.6
realtime/noble

not-affected

6.8.0-1008.19

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

6.14.0-13.13.2
esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-36.41
focal

released

5.4.0-36.41
groovy

not-affected

5.8.0-1.1
hirsute

not-affected

5.8.0-10.12+21.04.1
jammy

ignored

end of kernel support, was needs-triage
kinetic

not-affected

5.15.0-1007.7
lunar

not-affected

5.19.0-1004.4

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1015.17~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1015.17~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-17.17.1.1~22.04.1
mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-38.38.1~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

released

4.15.0-1089.98
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

jammy

DNE

mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

kinetic

not-affected

lunar

not-affected

5.19.0-1003.4

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.5.0-1007.8~22.04.1
mantic

DNE

noble

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1020.24
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1020.24
jammy

not-affected

5.15.0-1022.26
noble

DNE

oracular

DNE

plucky

DNE

Показывать по

EPSS

Процентиль: 18%
0.00056
Низкий

2.1 Low

CVSS2

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.1
redhat
больше 4 лет назад

Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by the user, like a removable device. This was introduced in kernel version 4.19 by commit d1d04ef ("ovl: stack file ops"). This was fixed in kernel version 5.8 by commits 56230d9 ("ovl: verify permissions in ovl_path_open()"), 48bd024 ("ovl: switch to mounter creds in readdir") and 05acefb ("ovl: check permission to open real file"). Additionally, commits 130fdbc ("ovl: pass correct flags for opening real directory") and 292f902 ("ovl: call secutiry hook in ovl_real_ioctl()") in kernel 5.8 might also be desired or necessary. These additional commits introduced a regression in overlay mounts within user namespaces which prevented access to files with ownership outside of the...

CVSS3: 5.1
nvd
больше 4 лет назад

Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by the user, like a removable device. This was introduced in kernel version 4.19 by commit d1d04ef ("ovl: stack file ops"). This was fixed in kernel version 5.8 by commits 56230d9 ("ovl: verify permissions in ovl_path_open()"), 48bd024 ("ovl: switch to mounter creds in readdir") and 05acefb ("ovl: check permission to open real file"). Additionally, commits 130fdbc ("ovl: pass correct flags for opening real directory") and 292f902 ("ovl: call secutiry hook in ovl_real_ioctl()") in kernel 5.8 might also be desired or necessary. These additional commits introduced a regression in overlay mounts within user namespaces which prevented access to files with ownership outside of the us

CVSS3: 4.4
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 5.1
debian
больше 4 лет назад

Overlayfs did not properly perform permission checking when copying up ...

github
около 3 лет назад

Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by the user, like a removable device. This was introduced in kernel version 4.19 by commit d1d04ef ("ovl: stack file ops"). This was fixed in kernel version 5.8 by commits 56230d9 ("ovl: verify permissions in ovl_path_open()"), 48bd024 ("ovl: switch to mounter creds in readdir") and 05acefb ("ovl: check permission to open real file"). Additionally, commits 130fdbc ("ovl: pass correct flags for opening real directory") and 292f902 ("ovl: call secutiry hook in ovl_real_ioctl()") in kernel 5.8 might also be desired or necessary. These additional commits introduced a regression in overlay mounts within user namespaces which prevented access to files with ownership outside of the...

EPSS

Процентиль: 18%
0.00056
Низкий

2.1 Low

CVSS2

5.1 Medium

CVSS3

Уязвимость CVE-2020-16120