CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 37.68% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- canonical/ubuntu linux · linux/linux kernel
- Source
- security@ubuntu.com
References
- http://seclists.org/oss-sec/2015/q2/717Mailing List, Third Party Advisory
- http://www.exploit-db.com/exploits/40688/Exploit, VDB Entry
- http://www.securityfocus.com/bid/75206Third Party Advisory, VDB Entry
- https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1328.htmlVendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2015-1328Third Party Advisory
- https://www.exploit-db.com/exploits/37292/
- http://seclists.org/oss-sec/2015/q2/717Mailing List, Third Party Advisory
- http://www.exploit-db.com/exploits/40688/Exploit, VDB Entry
- http://www.securityfocus.com/bid/75206Third Party Advisory, VDB Entry
- https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1328.htmlVendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2015-1328Third Party Advisory
- https://www.exploit-db.com/exploits/37292/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.