Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12109
HistoryJan 15, 2019 - 9:12 a.m.

Authorization Bypass

2019-01-1509:12:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.001

Percentile

45.5%

Linux kernel is vulnerable to authorization bypass. The ovl_setattr function in fs/overlayfs/inode.c attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

References