CVE-2016-2854

HIGH

Linux Kernel < 3.19.8 - Improper Privilege Management

Title source: rule
STIX 2.1

Description

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

Exploits (1)

exploitdb WORKING POC
by halfdog · textlocallinux
https://www.exploit-db.com/exploits/41761

References (4)

Core 4
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/02/24/9
Third Party Advisory mailing-list x_refsource_mlist
https://sourceforge.net/p/aufs/mailman/message/34864744/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96838

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
linux/linux_kernel 3.0.0 - 3.19.8
Published May 02, 2016
Tracked Since Feb 18, 2026