UBUNTU-CVE-2016-1576
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
02 / AFFECTED SOFTWARE
Affected packages
85 explicit affected versions
35 explicit affected versions
20 explicit affected versions
7 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
05 / REFERENCES
Further evidence
- http://www.halfdog.net/Security/2016/OverlayfsOverFusePrivilegeEscalation/
- https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/trusty/commit/?id=ce550fb847b34553e63ee95386de59a1096fbfc4
- https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/trusty/commit/?id=d77014a9527a4544797b9f1f2026b8e9fe032355
- https://ubuntu.com/security/CVE-2016-1576
- https://ubuntu.com/security/notices/USN-2907-1
- https://ubuntu.com/security/notices/USN-2907-2
- https://ubuntu.com/security/notices/USN-2908-1
- https://ubuntu.com/security/notices/USN-2908-2
- https://ubuntu.com/security/notices/USN-2908-3
- https://ubuntu.com/security/notices/USN-2909-1
- https://ubuntu.com/security/notices/USN-2910-1
- https://www.cve.org/CVERecord?id=CVE-2016-1576