Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24290
HistoryApr 10, 2020 - 12:51 a.m.

Privilege Escalation

2020-04-1000:51:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
30

0.0004 Low

EPSS

Percentile

5.1%

kernel is vulnerable to privilege escalation. A buffer overflow flaw was found in the ecryptfs_uid_hash() function in the Linux kernel eCryptfs implementation. On systems that have the eCryptfs netlink transport (Red Hat Enterprise Linux 5 does) or where the β€œ/dev/ecryptfs” file has world writable permissions (which it does not, by default, on Red Hat Enterprise Linux 5), a local, unprivileged user could use this flaw to cause a denial of service or possibly escalate their privileges.

References