The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2016-06-07T14:00:00

Updated: 2024-08-06T06:41:09.020Z

Reserved: 2015-07-01T00:00:00

Link: CVE-2015-5231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-06-07T14:06:05.510

Modified: 2024-11-21T02:32:36.520

Link: CVE-2015-5231

cve-icon Redhat

Severity : Low

Publid Date: 2015-08-25T00:00:00Z

Links: CVE-2015-5231 - Bugzilla