CVE-2015-0274
published 2015-03-16CVE-2015-0274: The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.44%
36.1th percentile
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.5-1 (bookworm) | linux 3.11.5-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.13.0-48.80 | 3.13.0-48.80 |
| linux | linux_kernel | >= 3.11 < 3.15 | 3.15 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-
Red Hat
kernel: xfs: replacing remote attributes memory corruption
vendor_redhat·2015-03-05·CVSS 7.2
CVE-2015-0274 [HIGH] kernel: xfs: replacing remote attributes memory corruption
kernel: xfs: replacing remote attributes memory corruption
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
A flaw was found in the way the Linux kernel's XFS file system handled replacing of remote attributes under certain conditions. A local user with access to XFS file system mount could potentially use this flaw to escalate their privileges on the system.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise 5 and 6. This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux
Debian
CVE-2015-0274: linux - The XFS implementation in the Linux kernel before 3.15 improperly uses an old si...
vendor_debian·2015·CVSS 7.2
CVE-2015-0274 [HIGH] CVE-2015-0274: linux - The XFS implementation in the Linux kernel before 3.15 improperly uses an old si...
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
Scope: local
bookworm: resolved (fixed in 3.11.5-1)
bullseye: resolved (fixed in 3.11.5-1)
forky: resolved (fixed in 3.11.5-1)
sid: resolved (fixed in 3.11.5-1)
trixie: resolved (fixed in 3.11.5-1)
GHSA
GHSA-65mm-97qv-fxq8: The XFS implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2015-0274 [HIGH] GHSA-65mm-97qv-fxq8: The XFS implementation in the Linux kernel before 3
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
OSV
linux vulnerabilities
osv·2015-03-24·CVSS 2.1
CVE-2015-0274 [LOW] linux vulnerabilities
linux vulnerabilities
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in the crypto subsystem when screening module names
for au
OSV
CVE-2015-0274: The XFS implementation in the Linux kernel before 3
osv·2015-03-16·CVSS 7.2
CVE-2015-0274 [HIGH] CVE-2015-0274: The XFS implementation in the Linux kernel before 3
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59http://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttp://www.securitytracker.com/id/1031853http://www.ubuntu.com/usn/USN-2543-1http://www.ubuntu.com/usn/USN-2544-1https://bugzilla.redhat.com/show_bug.cgi?id=1195248https://github.com/torvalds/linux/commit/8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59http://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttp://www.securitytracker.com/id/1031853http://www.ubuntu.com/usn/USN-2543-1http://www.ubuntu.com/usn/USN-2544-1https://bugzilla.redhat.com/show_bug.cgi?id=1195248https://github.com/torvalds/linux/commit/8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59
2015-03-16
Published