Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alexandre Oliva

#39502of 53,632
6.9Total CVSS
Vulnerabilities · 1
PT-2014-9016
6.9
2014-12-31
Linux · Linux Kernel · CVE-2014-9710
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 3.19 **Description** The issue allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations. This can occur in two scenarios: (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit. The estimated number of potentially affected devices worldwide is not specified. **Recommendations** For Linux kernel versions prior to 3.19, update to version 3.19 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive filesystem operations to minimize the risk of exploitation.