ZeroHour

CVE-2016-2853

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p58
Published
()
Modified
Description

The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

Vendors
linux
Products
linux kernel
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.