CVE-2014-9710

Modified
Published: 27 May 2015, 10:00
Last modified:06 Aug 2024, 13:55

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.9 MEDIUM
v2.0 (nvd)
EPSS Score
0.03% LOW
0% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 May 2015, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 13:55
Last Modified
Vulnerability information updated

Description

The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.

CVSS Metrics

  • v2.0MEDIUMScore: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.03% Percentile: 10%

Techniques & Countermeasures

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Affected Systems

  • linuxlinux_kernel

    < 3.10.83 | ≥ 3.11, < 3.12.45 | ≥ 3.13, < 3.14.47 | ≥ 3.15, < 3.16.35 | ≥ 3.17, < 3.18.19

References (7)