UBUNTU-CVE-2016-7097
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-7097
UBUNTU-CVE-2016-7097
Summary:
Details: The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions.
References: https://ubuntu.com/security/CVE-2016-7097, http://www.spinics.net/lists/linux-fsdevel/msg98328.html, http://www.spinics.net/lists/linux-fsdevel/msg101138.html, http://marc.info/?l=linux-fsdevel&m=147162313630259&w=2, https://bugzilla.redhat.com/show_bug.cgi?id=1368938, http://seclists.org/oss-sec/2016/q3/380, https://ubuntu.com/security/notices/USN-3146-1, https://ubuntu.com/security/notices/USN-3146-2, https://ubuntu.com/security/notices/USN-3147-1, https://ubuntu.com/security/notices/USN-3161-3, https://ubuntu.com/security/notices/USN-3161-4, https://ubuntu.com/security/notices/USN-3162-2, https://ubuntu.com/security/notices/USN-3422-1, https://ubuntu.com/security/notices/USN-3422-2, https://www.cve.org/CVERecord?id=CVE-2016-7097
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
