7.8
CVSSv3

CVE-2016-1575

Published: 02/05/2016 Updated: 18/04/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The overlayfs implementation in the Linux kernel up to and including 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

canonical ubuntu touch 15.04

canonical ubuntu linux 15.10

canonical ubuntu linux 16.04

canonical ubuntu linux 16.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu core 15.04

Vendor Advisories

USN-2908-2 introduced a regression in the Ubuntu 1510 Linux kernel backported to Ubuntu 1404 LTS ...
USN-2908-1 introduced a regression in the Linux kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
USN-2909-1 introduced a regression in the Ubuntu 1410 Linux kernel backported to Ubuntu 1404 LTS ...
USN-2910-1 introduced a regression in the Ubuntu 1504 Linux kernel backported to Ubuntu 1404 LTS ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...

Exploits

Source: wwwhalfdognet/Security/2016/UserNamespaceOverlayfsXattrSetgidPrivilegeEscalation/ ## Introduction ### Problem description: Linux user namespace allows to mount file systems as normal user, including the overlayfs As many of those features were not designed with namespaces in mind, this increase the attack surface of the Linux k ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: CVE-2021-3847: OverlayFS - Potential Privilege Escalation using overlays copy_up <!--X-Subject-Header-End--> <!--X-Head-of ...