The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-2671 | The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. |
Ubuntu USN |
USN-2907-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2907-2 | Linux kernel (Trusty HWE) vulnerabilities |
Ubuntu USN |
USN-2908-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2908-2 | Linux kernel (Wily HWE) vulnerabilities |
Ubuntu USN |
USN-2908-3 | Linux kernel (Raspberry Pi 2) vulnerabilities |
Ubuntu USN |
USN-2909-1 | Linux kernel (Utopic HWE) vulnerabilities |
Ubuntu USN |
USN-2910-1 | Linux kernel (Vivid HWE) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-08-05T23:02:11.745Z
Reserved: 2016-01-12T00:00:00
Link: CVE-2016-1576
No data.
Status : Deferred
Published: 2016-05-02T10:59:24.487
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-1576
No data.
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN