CVE-2016-10318
published 2017-04-04CVE-2016-10318: A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux…
PriorityP430medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.16%
80.4th percentile
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.4-1 (bookworm) | linux 4.7.4-1 (bookworm) |
| linux | linux_kernel | <= 4.7.3 | — |
| linux | linux_kernel | >= 0 < 4.7.4-1 | 4.7.4-1 |
| linux | linux_kernel | >= 0 < 4.7.4-1 | 4.7.4-1 |
| linux | linux_kernel | >= 0 < 4.7.4-1 | 4.7.4-1 |
| linux | linux_kernel | >= 0 < 4.7.4-1 | 4.7.4-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: User can assign an encryption policy to a directory owned by a different user
vendor_redhat·2016-09-08·CVSS 6.5
CVE-2016-10318 [MEDIUM] CWE-266 kernel: User can assign an encryption policy to a directory owned by a different user
kernel: User can assign an encryption policy to a directory owned by a different user
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.
Statement: This issue does not affect Red Hat Enterprise Linux 5, 6 and 7, MRG and realtime kernels.
Package: kerne
Debian
CVE-2016-10318: linux - A missing authorization check in the fscrypt_process_policy function in fs/crypt...
vendor_debian·2016·CVSS 6.5
CVE-2016-10318 [MEDIUM] CVE-2016-10318: linux - A missing authorization check in the fscrypt_process_policy function in fs/crypt...
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.
Scope: local
bookworm: resolved (fixed in 4.7.4-1)
bullseye: resolved (fixed in 4.7.4-1)
forky: resolved (fixed in 4.7.4-1)
sid: resolved (fixed in 4.7.4-1)
trixie: resolved (fixed in 4.7.4-1)
GHSA
GHSA-mcg2-4f7h-vc52: A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy
ghsa_unreviewed·2022-05-17
CVE-2016-10318 [MEDIUM] GHSA-mcg2-4f7h-vc52: A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.
OSV
CVE-2016-10318: A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy
osv·2017-04-04·CVSS 6.5
CVE-2016-10318 [MEDIUM] CVE-2016-10318: A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=163ae1c6ad6299b19e22b4a35d5ab24a89791a98http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.7.4http://www.securityfocus.com/bid/97404https://github.com/torvalds/linux/commit/163ae1c6ad6299b19e22b4a35d5ab24a89791a98http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=163ae1c6ad6299b19e22b4a35d5ab24a89791a98http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.7.4http://www.securityfocus.com/bid/97404https://github.com/torvalds/linux/commit/163ae1c6ad6299b19e22b4a35d5ab24a89791a98
2017-04-04
Published