| Vulnerability Name: | CVE-2016-1576 (CCN-114463) | ||||||||||||||||||||
| Assigned: | 2016-02-24 | ||||||||||||||||||||
| Published: | 2016-02-24 | ||||||||||||||||||||
| Updated: | 2022-04-18 | ||||||||||||||||||||
| Summary: | The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. | ||||||||||||||||||||
| CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-1576 Source: CCN Type: Linux Kernel GIT Repository Merge branch 'overlayfs-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/mszeredi/vfs Source: MISC Type: Mailing List, Patch, Vendor Advisory http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e9f57ebcba563e0cd532926cab83c92bb4d79360 Source: CONFIRM Type: Third Party Advisory http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-1576.html Source: MISC Type: Exploit, Third Party Advisory http://www.halfdog.net/Security/2016/OverlayfsOverFusePrivilegeEscalation/ Source: CCN Type: oss-sec Mailing List, Wed, 24 Feb 2016 06:03:35 +0000 Overlayfs over Fuse Privilege Escalation in USERNS Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160224 Overlayfs over Fuse Privilege Escalation in USERNS Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20211018 Re: CVE-2021-3847: OverlayFS - Potential Privilege Escalation using overlays copy_up Source: CONFIRM Type: Third Party Advisory https://bugs.launchpad.net/bugs/1535150 Source: XF Type: UNKNOWN linux-kernel-cve20161576-priv-esc(114463) Source: MISC Type: Mailing List, Patch, Third Party Advisory https://launchpadlibrarian.net/235300093/0005-overlayfs-Be-more-careful-about-copying-up-sxid-file.patch Source: MISC Type: Mailing List, Patch, Third Party Advisory https://launchpadlibrarian.net/235300225/0006-overlayfs-Propogate-nosuid-from-lower-and-upper-moun.patch | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||