USN-2318-1
Dashboard / Vulnerabilities / USN-2318-1
USN-2318-1
Summary: linux vulnerabilities
Details: Eric W. Biederman discovered a flaw with the mediation of mount flags in the Linux kernel's user namespace subsystem. An unprivileged user could exploit this flaw to by-pass mount restrictions, and potentially gain administrative privileges. (CVE-2014-5207) Kenton Varda discovered a flaw with read-only bind mounds when used with user namespaces. An unprivileged local user could exploit this flaw to gain full write privileges to a mount that should be read only. (CVE-2014-5206)
References: https://ubuntu.com/security/notices/USN-2318-1, https://ubuntu.com/security/CVE-2014-5206, https://ubuntu.com/security/CVE-2014-5207
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
