Lucene search

K
f5F5F5:K31603170
HistoryJun 22, 2017 - 12:00 a.m.

K31603170 : Linux kernel vulnerability CVE-2016-7097

2017-06-2200:00:00
my.f5.com
47

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Security Advisory Description

The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions. (CVE-2016-7097)

Impact

A local user may be allowed to gain group privileges by way of certain setgidapplications.