CVE-2015-1350Files or Directories Accessible to External Parties in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 79.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 13

Description

The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Debianlinux/linux_kernel< 4.8.11-1+3
Ubuntulinux/linux_kernel< 4.4.0-208.240
NVDlinux/linux_kernel3.03.19.8

Also affects: Enterprise Linux 5.0, 6.0, 7.0

Patches

🔴Vulnerability Details

6
GHSA
GHSA-m2mx-4jc6-3wh7: The VFS subsystem in the Linux kernel 32022-05-13
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2, linux-snapdragon vulnerabilities2021-04-13
OSV
linux-hwe vulnerabilities2017-07-21
Kernel
fs: Avoid premature clearing of capabilities2016-05-26
CVEList
CVE-2015-1350: The VFS subsystem in the Linux kernel 32016-05-02

📋Vendor Advisories

4
Ubuntu
Linux kernel vulnerabilities2021-04-13
Ubuntu
Linux kernel (HWE) vulnerabilities2017-07-21
Debian
CVE-2015-1350: linux - The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirem...2015
Red Hat
kernel: denial of service in notify_change for filesystem xattrs2014-11-21

💬Community

2
Bugzilla
CVE-2015-1350 kernel: denial of service in notify_change for filesystem xattrs [fedora-all]2015-02-16
Bugzilla
CVE-2015-1350 kernel: denial of service in notify_change for filesystem xattrs2015-01-23
CVE-2015-1350 — Linux Kernel vulnerability | cvebase