CVE-2016-1576
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
Affected (8)
Products: Canonical: Ubuntu Core, Ubuntu Linux, Ubuntu Touch · Linux: Linux Kernel
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 15.04 | |
| Version 12.04 | |
| Version 15.04 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.5.2 |
References (16)
Source: security@ubuntu.com
Mailing ListPatchVendor Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
ExploitThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListPatchThird Party Advisory
Source: security@ubuntu.com
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Timeline
No history available yet.