SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-4014

The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated…

MEDIUM 6.2EPSS 3.30%

Does this matter?

Lower severity and a low EPSS score (3.30%). Track it; it rarely justifies an emergency change on its own.

Description

The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.

CVSS 2.0
6.2 MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
EPSS
3.30% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
linux/linux kernel
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.