CVE-2016-1575 PUBLISHED

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

EPSS 0.52% · 66.8th percentile

Risk Scores

EPSS Score
0.52%
66.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-wily4.2.0-27.32~14.04.1, 4.2.0-25.30~14.04.1, 4.2.0-23.28~14.04.1
Ubuntu:14.04:LTSlinux-lts-utopic3.16.0-31.43~14.04.1, 3.16.0-33.44~14.04.1, 3.16.0-34.45~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-28.30~14.04.1, 3.19.0-30.33~14.04.1, 3.19.0-30.34~14.04.1
Ubuntu:14.04:LTSlinux3.13.0-53.89, 3.13.0-54.91, 3.13.0-55.92

Timeline

References

Open in Interactive Console →