VulnerabilityModified
CVE-2018-16597
Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
MEDIUM 5.5EPSS 0.54%
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- linux/linux kernel · netapp/active iq performance analytics services · netapp/element software · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- http://www.securityfocus.com/bid/105394Third Party Advisory, VDB Entry
- https://bugzilla.suse.com/show_bug.cgi?id=1106512Issue Tracking, Patch, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0ca3d70e8d3cf81e2255a217f7ca402f5ed0862Patch, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jul/33
- https://security.netapp.com/advisory/ntap-20190204-0001/Patch, Third Party Advisory
- https://support.f5.com/csp/article/K22691834Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- http://www.securityfocus.com/bid/105394Third Party Advisory, VDB Entry
- https://bugzilla.suse.com/show_bug.cgi?id=1106512Issue Tracking, Patch, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0ca3d70e8d3cf81e2255a217f7ca402f5ed0862Patch, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jul/33
- https://security.netapp.com/advisory/ntap-20190204-0001/Patch, Third Party Advisory
- https://support.f5.com/csp/article/K22691834Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.