CVE-2014-4014
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated…
Does this matter?
Lower severity and a low EPSS score (3.30%). Track it; it rarely justifies an emergency change on its own.
Description
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.
- CVSS 2.0
- 6.2 MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 3.30% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=23adbe12ef7d3d4195e80800ab36b37bee28cd03
- http://secunia.com/advisories/59220Third Party Advisory
- http://www.exploit-db.com/exploits/33824Third Party Advisory, VDB Entry
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/06/10/4Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/67988Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030394Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1107966Issue Tracking, Third Party Advisory
- https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03Third Party Advisory
- https://source.android.com/security/bulletin/2016-12-01.htmlThird Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=23adbe12ef7d3d4195e80800ab36b37bee28cd03
- http://secunia.com/advisories/59220Third Party Advisory
- http://www.exploit-db.com/exploits/33824Third Party Advisory, VDB Entry
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/06/10/4Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/67988Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030394Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1107966Issue Tracking, Third Party Advisory
- https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03Third Party Advisory
- https://source.android.com/security/bulletin/2016-12-01.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.