PT-2015-7817 · Linux+5 · Linux Kernel+5

Rebel

·

Published

2015-12-28

·

Updated

2025-09-29

·

CVE-2015-8660

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.3.3 Linux kernel (affected versions not specified)
Description The issue allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. This is due to the ovl setattr function in fs/overlayfs/inode.c attempting to merge distinct setattr operations.
Recommendations For versions prior to 4.3.3, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability in other affected versions.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2016-1018
ALT-PU-2016-1485
CESA-2016_1539
CVE-2015-8660
ELSA-2016-1539
ELSA-2016-3593
MGASA-2016-0005
MGASA-2016-0014
MGASA-2016-0015
OPENSUSE-SU-2024:10128-1
RHSA-2016:1532
RHSA-2016:1539
RHSA-2016:1541
RHSA-2016_1539
RHSA-2016_1541
SUSE-SU-2016:0585-1
SUSE-SU-2016:0751-1
SUSE-SU-2016:0752-1
SUSE-SU-2016:0755-1
SUSE-SU-2016_0585-1
USN-2857-1
USN-2857-2
USN-2858-1
USN-2858-2
USN-2858-3

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu