Description
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.
References (10)
Core 10
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147864.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2515-1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/71154
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2518-1
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:058
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147973.html
Exploit x_refsource_confirm
http://thread.gmane.org/gmane.linux.man/7385/
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2517-1
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/11/20/4
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2516-1
Scores
EPSS
0.0049
EPSS Percentile
39.8%
Details
CWE
CWE-264
Status
published
Products (44)
linux/linux_kernel
3.0 rc1 (7 CPE variants)
linux/linux_kernel
3.0.1
linux/linux_kernel
3.0.2
linux/linux_kernel
3.0.3
linux/linux_kernel
3.0.4
linux/linux_kernel
3.0.5
linux/linux_kernel
3.0.6
linux/linux_kernel
3.0.7
linux/linux_kernel
3.0.8
linux/linux_kernel
3.0.9
... and 34 more
Published
Nov 30, 2014
Tracked Since
Feb 18, 2026