UBUNTU-CVE-2015-2925
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-2925
UBUNTU-CVE-2015-2925
Summary:
Details: The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."
References: https://ubuntu.com/security/CVE-2015-2925, http://permalink.gmane.org/gmane.linux.kernel.containers/29173, http://permalink.gmane.org/gmane.linux.kernel.containers/29177, http://article.gmane.org/gmane.linux.kernel.stable/151103, https://ubuntu.com/security/notices/USN-2794-1, https://ubuntu.com/security/notices/USN-2792-1, https://ubuntu.com/security/notices/USN-2795-1, https://ubuntu.com/security/notices/USN-2799-1, https://ubuntu.com/security/notices/USN-2796-1, https://ubuntu.com/security/notices/USN-2798-1, https://ubuntu.com/security/notices/USN-2797-1, https://www.cve.org/CVERecord?id=CVE-2015-2925
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
