SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-8989

The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the…

MEDIUM 4.6EPSS 0.50%

Does this matter?

Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.

Description

The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
0.50% probability · 41th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
linux/linux kernel
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.