Lucene search

K
cve[email protected]CVE-2015-2925
HistoryNov 16, 2015 - 11:59 a.m.

CVE-2015-2925

2015-11-1611:59:00
CWE-254
web.nvd.nist.gov
90
linux
kernel
cve-2015-2925
security
vulnerability
double-chroot attack
nvd

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a “double-chroot attack.”

Affected configurations

NVD
Node
linuxlinux_kernelRange4.2.3

References

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%