Bug 982780 (CVE-2016-2854) - VUL-0: CVE-2016-2854: kernel: aufs: The aufs module for the Linux kernel 3.x and 4.x does not properly maintainPOSIX ACL xattr data, wh...
Summary: VUL-0: CVE-2016-2854: kernel: aufs: The aufs module for the Linux kernel 3.x ...
Status: RESOLVED INVALID
Alias: CVE-2016-2854
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: E-mail List
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/162731/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-06-02 13:58 UTC by Marcus Meissner
Modified: 2016-06-02 14:05 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2016-06-02 13:58:56 UTC
CVE-2016-2854

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain
POSIX ACL xattr data, which allows local users to gain privileges by leveraging
a group-writable setgid directory.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2854
http://seclists.org/oss-sec/2016/q1/542
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2854.html
http://www.cvedetails.com/cve/CVE-2016-2854/
Comment 1 Marcus Meissner 2016-06-02 13:59:46 UTC
this is actually a seperate not in kernel filesystem which we never shipped.