CVE-2015-3339

Linux kernel <3.19.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.

References (18)

Core 18
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032412
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158804.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1214030
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3237
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157897.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/20/5
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1272.html

Scores

EPSS 0.0003
EPSS Percentile 9.1%

Details

CWE
CWE-362
Status published
Products (3)
debian/debian_linux 7.0
debian/debian_linux 8.0
linux/linux_kernel < 3.19.5
Published May 27, 2015
Tracked Since Feb 18, 2026