CVE-2015-1350

MEDIUM

Linux Kernel 3.0-3.19.7 - Local Denial of Service via VFS setattr Capability Stripping

Title source: llm
STIX 2.1

Description

The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.

References (5)

Core 5
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1185139
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76075
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://marc.info/?l=linux-kernel&m=142153722930533&w=2
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=770492
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/01/24/5

Scores

CVSS v3 5.5
EPSS 0.0049
EPSS Percentile 38.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-552
Status published
Products (5)
linux/linux_kernel 3.0 - 3.19.8
redhat/enterprise_linux 5.0
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
redhat/enterprise_mrg 2.0
Published May 02, 2016
Tracked Since Feb 18, 2026