ZeroHour

CVE-2016-1575

PoC
CVSS 3.1
7.8 high
EPSS
<1%p58
Published
()
Modified
Description

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

Vendors
linuxcanonical
Products
linux kernel, ubuntu core, ubuntu linux, ubuntu touch
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.