CVE-2010-2071

Linux Kernel < 2.6.34 - Unauthenticated ACL Bypass via btrfs_xattr_set_acl

Title source: llm
STIX 2.1

Description

The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl.

References (4)

Core 4
Core References
Exploit, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://lkml.org/lkml/2010/5/17/544
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/06/14/2
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/06/11/3

Scores

EPSS 0.0047
EPSS Percentile 38.3%

Details

CWE
CWE-264
Status published
Products (1)
linux/linux_kernel < 2.6.34
Published Jun 16, 2010
Tracked Since Feb 18, 2026