Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31595
HistoryAug 12, 2021 - 3:38 p.m.

Privilege Escalation

2021-08-1215:38:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
linux
privilege escalation
overlayfs
validation
user namespaces
file capabilities
ubuntu kernel
elevated privileges

EPSS

0.008

Percentile

82.3%

linux-gkeop is vulnerable to privilege escalation. The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.