CVE-2015-1350
Vulnerability Summary
Timeline
Description
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.49%• Percentile: 41%
Techniques & Countermeasures
- CWE-552•Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Affected Systems
- debian•linux
< 4.8.11-1 | < 4.8.11-1 | < 4.8.11-1 | < 4.8.11-1
- ubuntu•linux
all | < 4.4.0-208.240
- ubuntu•linux-aws
< 4.4.0-1090.94 | < 4.4.0-1126.140
- ubuntu•linux-azure-fde
all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1060.66 | all
- ubuntu•linux-hwe
< 4.10.0-32.36~16.04.1
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1091.100
- ubuntu•linux-lts-xenial
< 4.4.0-208.240~14.04.1
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1150.161
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all
- ubuntu•linux-snapdragon
< 4.4.0-1154.164 | < 4.15.0-1053.57
- linux•linux_kernel
≥ 3.0, ≤ 3.19.8
- redhat•enterprise_linux
5.0 | 6.0 | 7.0
- redhat•enterprise_mrg
2.0
References (10)
- https://bugzilla.redhat.com/show_bug.cgi?id=1185139
- http://www.securityfocus.com/bid/76075
- http://marc.info/?l=linux-kernel&m=142153722930533&w=2
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=770492
- http://www.openwall.com/lists/oss-security/2015/01/24/5
- https://ubuntu.com/security/CVE-2015-1350
- https://ubuntu.com/security/notices/USN-3361-1
- https://ubuntu.com/security/notices/USN-4904-1
- https://www.cve.org/CVERecord?id=CVE-2015-1350
- https://security-tracker.debian.org/tracker/CVE-2015-1350