Bugzilla – Bug 982780
VUL-0: CVE-2016-2854: kernel: aufs: The aufs module for the Linux kernel 3.x and 4.x does not properly maintainPOSIX ACL xattr data, wh...
Last modified: 2016-06-02 14:05:43 UTC
CVE-2016-2854 The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2854 http://seclists.org/oss-sec/2016/q1/542 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2854.html http://www.cvedetails.com/cve/CVE-2016-2854/
this is actually a seperate not in kernel filesystem which we never shipped.