CVE-2014-8989

Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 30 Nov 2014, 01:00
Last modified:06 Aug 2024, 13:33

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
4.6 MEDIUM
v2.0 (nvd)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

30 Nov 2014, 01:00
Published
Vulnerability first disclosed
06 Aug 2024, 13:33
Last Modified
Vulnerability information updated

Description

The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.

CVSS Metrics

  • v2.0MEDIUMScore: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.03% Percentile: 8%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • linuxlinux_kernel

    ≤ 3.17.3 | 3.0:rc1 | 3.0:rc2 | 3.0:rc3 | 3.0:rc4 | 3.0:rc5 | 3.0:rc6 | 3.0:rc7 | 3.0.1 | 3.0.2 | 3.0.3 | 3.0.4 | 3.0.5 | 3.0.6 | 3.0.7 | 3.0.8 | 3.0.9 | 3.0.10 | 3.0.11 | 3.0.12 | 3.0.13 | 3.0.14 | 3.0.15 | 3.0.16 | 3.0.17 | 3.0.18 | 3.0.19 | 3.0.20 | 3.0.21 | 3.0.22 | 3.0.23 | 3.0.24 | 3.0.25 | 3.0.26 | 3.0.27 | 3.0.28 | 3.0.29 | 3.0.30 | 3.0.31 | 3.0.32 | 3.0.33 | 3.0.34 | 3.0.35 | 3.0.36 | 3.0.37 | 3.0.38 | 3.0.39 | 3.0.40 | 3.0.41 | 3.0.42 | 3.0.43 | 3.0.44 | 3.0.45 | 3.0.46 | 3.0.47 | 3.0.48 | 3.0.49 | 3.0.50 | 3.0.51 | 3.0.52 | 3.0.53 | 3.0.54 | 3.0.55 | 3.0.56 | 3.0.57 | 3.0.58 | 3.0.59 | 3.0.60 | 3.0.61 | 3.0.62 | 3.0.63 | 3.0.64 | 3.0.65 | 3.0.66 | 3.0.67 | 3.0.68 | 3.1 | 3.1:rc1 | 3.1:rc2 | 3.1:rc3 | 3.1:rc4 | 3.1.1 | 3.12 | 3.13 | 3.14 | 3.15 | 3.16 | 3.17 | 3.18 | 3.19 | 3.1.10 | 3.2 | 3.2:rc2 | 3.2:rc3 | 3.10 | 3.10.0 | 3.10.1 | 3.10.2 | 3.10.3 | 3.10.4 | 3.10.5 | 3.10.6 | 3.10.7 | 3.10.8 | 3.10.9 | 3.10.10 | 3.10.11 | 3.10.12 | 3.10.13 | 3.10.14 | 3.10.15 | 3.10.16 | 3.10.17 | 3.10.18 | 3.10.19 | 3.10.20 | 3.10.21 | 3.10.22 | 3.10.23 | 3.10.24 | 3.10.25 | 3.10.26 | 3.10.27 | 3.10.28 | 3.10.29 | 3.11.1 | 3.11.2 | 3.11.3 | 3.11.4 | 3.11.5 | 3.11.6 | 3.11.7 | 3.11.8 | 3.11.9 | 3.11.10 | 3.12.1 | 3.12.2 | 3.12.3 | 3.12.4 | 3.12.5 | 3.12.6 | 3.12.7 | 3.12.8 | 3.12.9 | 3.12.10 | 3.12.11 | 3.12.12 | 3.12.13 | 3.12.14 | 3.12.15 | 3.12.16 | 3.12.17 | 3.13.1 | 3.13.2 | 3.13.3 | 3.13.4 | 3.13.5 | 3.13.6 | 3.13.7 | 3.13.8 | 3.13.9 | 3.13.10 | 3.13.11 | 3.14:rc1 | 3.14:rc2 | 3.14:rc3 | 3.14:rc4 | 3.14:rc5 | 3.14:rc6 | 3.14:rc7 | 3.14:rc8 | 3.14.1 | 3.14.2 | 3.14.3 | 3.14.4 | 3.14.5 | 3.15.1 | 3.15.2 | 3.15.3 | 3.15.4 | 3.15.5 | 3.15.6 | 3.15.7 | 3.15.8 | 3.16.0 | 3.16.1 | 3.17.1 | 3.17.2

References (10)