UBUNTU-CVE-2015-1328
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-1328
UBUNTU-CVE-2015-1328
Summary:
Details: The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.
References: https://ubuntu.com/security/CVE-2015-1328, https://ubuntu.com/security/notices/USN-2640-1, https://ubuntu.com/security/notices/USN-2641-1, https://ubuntu.com/security/notices/USN-2642-1, https://ubuntu.com/security/notices/USN-2643-1, https://ubuntu.com/security/notices/USN-2644-1, https://ubuntu.com/security/notices/USN-2645-1, https://ubuntu.com/security/notices/USN-2646-1, https://ubuntu.com/security/notices/USN-2647-1, https://www.cve.org/CVERecord?id=CVE-2015-1328
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
