UBUNTU-CVE-2016-1575
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-1575
UBUNTU-CVE-2016-1575
Summary:
Details: The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
References: https://ubuntu.com/security/CVE-2016-1575, http://www.halfdog.net/Security/2016/UserNamespaceOverlayfsXattrSetgidPrivilegeEscalation/, https://ubuntu.com/security/notices/USN-2910-1, https://ubuntu.com/security/notices/USN-2908-3, https://ubuntu.com/security/notices/USN-2908-1, https://ubuntu.com/security/notices/USN-2907-1, https://ubuntu.com/security/notices/USN-2909-1, https://ubuntu.com/security/notices/USN-2907-2, https://ubuntu.com/security/notices/USN-2908-2, https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/trusty/commit/?id=4dc7ebf4284cdc90e8f3cd617ed247aade2ca39f, https://www.cve.org/CVERecord?id=CVE-2016-1575
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
