ZeroHour

CVE-2016-2854

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p59
Published
()
Modified
Description

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

Vendors
linux
Products
linux kernel
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.