CVE-2012-0055

HIGH

Linux Kernel < 3.0.0 - Missing Authorization in OverlayFS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0055. PoCs published by Gary Poster.

AI-analyzed exploit summary This exploit leverages a local security-bypass vulnerability in OverlayFS (CVE-2012-0055) by manipulating cgroup device restrictions to bypass security policies. It demonstrates unauthorized device access via overlay mounts and cgroup configurations.

Description

OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Gary Poster · bashlocallinux
https://www.exploit-db.com/exploits/36571

This exploit leverages a local security-bypass vulnerability in OverlayFS (CVE-2012-0055) by manipulating cgroup device restrictions to bypass security policies. It demonstrates unauthorized device access via overlay mounts and cgroup configurations.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Linux Kernel (OverlayFS)
Auth required
Prerequisites: Local access to the system · Ability to create cgroups and mount overlay filesystems
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/01/17/11
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-0055
Third Party Advisory x_refsource_misc
https://access.redhat.com/security/cve/cve-2012-0055
Third Party Advisory x_refsource_confirm
http://www.ubuntu.com/usn/USN-1363-1
Third Party Advisory x_refsource_confirm
http://www.ubuntu.com/usn/USN-1364-1
Third Party Advisory x_refsource_confirm
http://www.ubuntu.com/usn/USN-1384-1
Exploit, Third Party Advisory x_refsource_confirm
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/915941

Scores

CVSS v3 7.8
EPSS 0.0124
EPSS Percentile 65.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (3)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 11.10
linux/linux_kernel < 3.0.0
Published Feb 19, 2020
Tracked Since Feb 18, 2026