UBUNTU-CVE-2014-9710
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9710
UBUNTU-CVE-2014-9710
Summary:
Details: The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
References: https://ubuntu.com/security/CVE-2014-9710, http://www.openwall.com/lists/oss-security/2015/03/24/11, https://ubuntu.com/security/notices/USN-2615-1, https://ubuntu.com/security/notices/USN-2616-1, https://ubuntu.com/security/notices/USN-2662-1, https://ubuntu.com/security/notices/USN-2663-1, https://www.cve.org/CVERecord?id=CVE-2014-9710
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
