CVE-2015-2925
Advisory lineage Upstream: 0 Downstream: 22
Modified
Published: 16 Nov 2015, 11:00
Last modified:06 Aug 2024, 05:32
Vulnerability Summary
Overall Risk (default)
medium
28/100 CVSS Score
6.9 MEDIUM
v2.0 (nvd)
EPSS Score
0.75% LOW
1% probability -0.21%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
16 Nov 2015, 11:00
Published
Vulnerability first disclosed
06 Aug 2024, 05:32
Last Modified
Vulnerability information updated
Description
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."
CVSS Metrics
- v2.0•MEDIUM•Score: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.75%• Percentile: 73%
Affected Systems
- canonical•ubuntu_linux
12.04 | 14.04 | 15.04
- debian•debian_linux
7.0 | 8.0
- linux•linux_kernel
< 3.2.72 | ≥ 3.3, < 3.4.110 | ≥ 3.5, < 3.10.91 | ≥ 3.11, < 3.12.49 | ≥ 3.13, < 3.14.55 | ≥ 3.15, < 3.16.35 | ≥ 3.17, < 3.18.23 | ≥ 3.19, < 4.1.11 | ≥ 4.2, < 4.2.4
References (34)
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.html
- http://rhn.redhat.com/errata/RHSA-2015-2636.html
- http://www.debian.org/security/2015/dsa-3372
- http://permalink.gmane.org/gmane.linux.kernel.containers/29173
- http://rhn.redhat.com/errata/RHSA-2016-0068.html
- http://pkgs.fedoraproject.org/cgit/kernel.git/commit/?h=f22&id=520b64102de2f184036024b2a53de2b67463bd78
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.html
- http://www.ubuntu.com/usn/USN-2792-1
- http://www.securityfocus.com/bid/73926
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.html
- http://www.debian.org/security/2015/dsa-3364
- http://www.ubuntu.com/usn/USN-2794-1
- http://www.ubuntu.com/usn/USN-2799-1
- http://www.ubuntu.com/usn/USN-2795-1
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://permalink.gmane.org/gmane.linux.kernel.containers/29177
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.html
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cde93be45a8a90d8c264c776fab63487b5038a65
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.html
- http://www.openwall.com/lists/oss-security/2015/04/04/4
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.2.4
- https://bugzilla.redhat.com/show_bug.cgi?id=1209367
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=397d425dc26da728396e66d392d5dcb8dac30c37
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.html
- https://github.com/torvalds/linux/commit/cde93be45a8a90d8c264c776fab63487b5038a65
- https://bugzilla.redhat.com/show_bug.cgi?id=1209373
- https://github.com/torvalds/linux/commit/397d425dc26da728396e66d392d5dcb8dac30c37
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.html
- http://www.ubuntu.com/usn/USN-2798-1