CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
Percentile
5.1%
The do_remount function in fs/namespace.c in the Linux kernel through
3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a
bind mount, which allows local users to bypass an intended read-only
restriction and defeat certain sandbox protection mechanisms via a “mount
-o remount” command within a user namespace.
Author | Note |
---|---|
jdstrand | android kernels (goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 13.10 preview kernels android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.04 preview kernels |
apw | The existing break-fix appears to point to some self-tests break-fix: - db181ce011e3c033328608299cd6fac06ea50130 actual fix appears to be: a6138db815df5ee542d848318e5dae681590fccd |
jdstrand | linux-lts-saucy no longer receives official support |