PT-2016-4868 · Linux+2 · Linux Kernel+2

Halfdog

·

Published

2016-02-22

·

Updated

2022-04-18

·

CVE-2016-1576

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.5.2
Description The issue is related to the overlayfs implementation in the Linux kernel, which does not properly restrict the mount namespace. This allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem and then executing a crafted setuid program.
Recommendations For Linux kernel versions prior to 4.5.2, update to a version that contains the fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2016-1470
ALT-PU-2017-1330
CVE-2016-1576
USN-2907-1
USN-2907-2
USN-2908-1
USN-2908-2
USN-2908-3
USN-2909-1
USN-2909-2
USN-2910-1
USN-2910-2

Affected Products

Alt Linux
Linux Kernel
Ubuntu