CVE-2016-1576
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- canonical/ubuntu core · canonical/ubuntu linux · canonical/ubuntu touch · linux/linux kernel
- Source
- security@ubuntu.com
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e9f57ebcba563e0cd532926cab83c92bb4d79360Mailing List, Patch, Vendor Advisory
- http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-1576.htmlThird Party Advisory
- http://www.halfdog.net/Security/2016/OverlayfsOverFusePrivilegeEscalation/Exploit, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/02/24/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/10/18/1Mailing List, Third Party Advisory
- https://bugs.launchpad.net/bugs/1535150Third Party Advisory
- https://launchpadlibrarian.net/235300093/0005-overlayfs-Be-more-careful-about-copying-up-sxid-file.patchMailing List, Patch, Third Party Advisory
- https://launchpadlibrarian.net/235300225/0006-overlayfs-Propogate-nosuid-from-lower-and-upper-moun.patchMailing List, Patch, Third Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e9f57ebcba563e0cd532926cab83c92bb4d79360Mailing List, Patch, Vendor Advisory
- http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-1576.htmlThird Party Advisory
- http://www.halfdog.net/Security/2016/OverlayfsOverFusePrivilegeEscalation/Exploit, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/02/24/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/10/18/1Mailing List, Third Party Advisory
- https://bugs.launchpad.net/bugs/1535150Third Party Advisory
- https://launchpadlibrarian.net/235300093/0005-overlayfs-Be-more-careful-about-copying-up-sxid-file.patchMailing List, Patch, Third Party Advisory
- https://launchpadlibrarian.net/235300225/0006-overlayfs-Propogate-nosuid-from-lower-and-upper-moun.patchMailing List, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.