VDB

DEBIAN-CVE-2014-4014

DEBIAN-CVE-2014-4014 PUBLISHED

The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.

Affected Products

VendorProductVersions
Debian:13linux0, 0, 0
Debian:11linux0, 0, 0
Debian:14linux0, 0, 0
Debian:12linux0, 0, 0

Timeline

  • Jun 23, 2014 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›