187
VMScore

CVE-2015-4176

Published: 02/05/2016 Updated: 05/05/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

fs/namespace.c in the Linux kernel prior to 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

A flaw was found in the Linux kernel where the deletion of a file or directory could trigger an unmount and reveal data under a mount point This flaw was inadvertently introduced with the new feature of being able to lazily unmount a mount tree when using file system user namespaces ...