CVE-2016-1237
published 2016-06-29CVE-2016-1237: nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.36%
29.1th percentile
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.6.2-2 (bookworm) | linux 4.6.2-2 (bookworm) |
| linux | linux_kernel | <= 4.6.3 | — |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.6.2-2 | 4.6.2-2 |
| linux | linux_kernel | >= 0 < 4.4.0-36.55 | 4.4.0-36.55 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3gq-m2h3-69wv: nfsd in the Linux kernel through 4
ghsa_unreviewed·2022-05-17
CVE-2016-1237 [MEDIUM] CWE-284 GHSA-r3gq-m2h3-69wv: nfsd in the Linux kernel through 4
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
OSV
linux-lts-xenial vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3070-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with
OSV
linux-snapdragon vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remot
OSV
linux-raspi2 vulnerabilities
osv·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote at
OSV
linux vulnerabilities
osv·2016-08-29·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implementation's handling of
challenge acks in the Linux kernel. A remote attacker
OSV
linux-lts-vivid vulnerabilities
osv·2016-08-10·CVSS 5.5
CVE-2016-1237 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-4794)
Kangjie Lu discovered an information leak in the netlink implementatio
OSV
CVE-2016-1237: nfsd in the Linux kernel through 4
osv·2016-06-29·CVSS 5.5
CVE-2016-1237 [MEDIUM] CVE-2016-1237: nfsd in the Linux kernel through 4
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a fla
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-08-30·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3070-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linu
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-08-29·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
Kangjie Lu discovered an information leak in the Reliable Datagram Sockets
(RDS) implementation in the Linux kernel. A local attacker could use this
to obtain potentially sensitive information from kernel memory.
(CVE-2016-5244)
James Patrick-Evans discovered that the airspy USB device driver in the
Linux kernel did not properly handle certain error conditions. An attacker
with physical access could use this to cause a denial of service (memory
consumption). (CVE-2016-5400)
Yue Cao et al discovered a flaw in the TCP implement
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-08-10·CVSS 5.5
CVE-2016-1237 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A missing permission check when settings ACLs was discovered in nfsd. A
local user could exploit this flaw to gain access to any file by setting an
ACL. (CVE-2016-1237)
It was discovered that the keyring implementation in the Linux kernel did
not ensure a data structure was initialized before referencing it after an
error condition occurred. A local attacker could use this to cause a denial
of service (system crash). (CVE-2016-4470)
Sasha Levin discovered that a use-after-free existed in the percpu
allocator in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-4
Red Hat
kernel: Missing check for permissions when setting ACL
vendor_redhat·2016-06-24·CVSS 5.5
CVE-2016-1237 [MEDIUM] CWE-863 kernel: Missing check for permissions when setting ACL
kernel: Missing check for permissions when setting ACL
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
It was found that nfsd is missing permissions check when setting ACL on files, this may allow a local users to gain access to any file by setting a crafted ACL.
Statement: This issue does not affect any of Red Hat's shipping products.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2016-1237: linux - nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended fil...
vendor_debian·2016·CVSS 5.5
CVE-2016-1237 [MEDIUM] CVE-2016-1237: linux - nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended fil...
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
Scope: local
bookworm: resolved (fixed in 4.6.2-2)
bullseye: resolved (fixed in 4.6.2-2)
forky: resolved (fixed in 4.6.2-2)
sid: resolved (fixed in 4.6.2-2)
trixie: resolved (fixed in 4.6.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1237 kernel: Missing check for permissions when setting ACL [fedora-all]
bugzilla·2016-06-28·CVSS 5.5
CVE-2016-1237 [MEDIUM] CVE-2016-1237 kernel: Missing check for permissions when setting ACL [fedora-all]
CVE-2016-1237 kernel: Missing check for permissions when setting ACL [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2016-1237 kernel: Missing check for permissions when setting ACL
bugzilla·2016-06-28·CVSS 5.5
CVE-2016-1237 [MEDIUM] CVE-2016-1237 kernel: Missing check for permissions when setting ACL
CVE-2016-1237 kernel: Missing check for permissions when setting ACL
It was found that nfsd is missing permissions check when setting ACL, which allows local users to gain access to any file by setting ACL.
Introduced in v3.14-rc1 by following commit:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4ac7249ea5a0ceef9f8269f63f33cc873c3fac61
Upstream fix:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=999653786df6954a31044528ac3f7a5dadca08f4
Prerequisite for the fix:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=485e71e8fb6356c08c7fc6bcce4bf02c9a9a663f
CVE request:
http://seclists.org/oss-sec/2016/q2/602
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1350847]
--
Bugzilla
CVE-2015-8898 ImageMagick: Prevent NULL pointer access in magick/constitute.c
bugzilla·2016-06-09·CVSS 5.5
CVE-2015-8898 [MEDIUM] CVE-2015-8898 ImageMagick: Prevent NULL pointer access in magick/constitute.c
CVE-2015-8898 ImageMagick: Prevent NULL pointer access in magick/constitute.c
A null pointer dereference flaw has been discovered in the constitute image
functionality, which could lead to an application crash.
External references:
https://github.com/ImageMagick/ImageMagick/pull/34
http://seclists.org/oss-sec/2016/q2/459
Patch:
https://github.com/ImageMagick/ImageMagick/pull/34/commits/aa785715d46f2b18b60c652a177c57bc8f0a0a68
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1344266]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1237 https://access.redhat.com/errata/RHSA-2016:1237
Bugzilla
CVE-2015-8897 ImageMagick: Crash due to out of bounds error in SpliceImage
bugzilla·2016-06-09·CVSS 5.5
CVE-2015-8897 [MEDIUM] CVE-2015-8897 ImageMagick: Crash due to out of bounds error in SpliceImage
CVE-2015-8897 ImageMagick: Crash due to out of bounds error in SpliceImage
An error was discovered in the ImageMagick -split functionality. Processing
a specially crafted image using this functionality could lead to an application crash.
External references:
http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=28466
http://seclists.org/oss-sec/2016/q2/459
Patch:
http://git.imagemagick.org/repos/ImageMagick/commit/e00cf211070e7f150a3da77932b8620c89bb9225
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1344273]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1237 https://access.redhat.com/errata/RHSA-2016:1237
Bugzilla
CVE-2016-5239 ImageMagick,GraphicsMagick: Gnuplot delegate vulnerability allowing command injection
bugzilla·2016-05-09·CVSS 9.8
CVE-2016-5239 [CRITICAL] CVE-2016-5239 ImageMagick,GraphicsMagick: Gnuplot delegate vulnerability allowing command injection
CVE-2016-5239 ImageMagick,GraphicsMagick: Gnuplot delegate vulnerability allowing command injection
It was found that gnuplot delegate functionality in ImageMagick and GraphicsMagick allows system command injection while interpreting gnuplot files.
Upstream patch (ImageMagick):
http://git.imagemagick.org/repos/ImageMagick/commit/70a2cf326ed32bedee144b961005
Upstream patch (GraphicsMagick):
http://hg.code.sf.net/p/graphicsmagick/code/rev/45998a25992d
Discussion:
Public via:
http://www.openwall.com/lists/oss-security/2016/05/09/1
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1237 https://access.redhat.com/errata/RHSA-2016:1237
---
To clear things up a bit:
* gnuplot files should not be processed
Bugzilla
CVE-2016-5240 ImageMagick: SVG converting issue resulting in DoS
bugzilla·2016-05-05·CVSS 5.5
CVE-2016-5240 [MEDIUM] CVE-2016-5240 ImageMagick: SVG converting issue resulting in DoS
CVE-2016-5240 ImageMagick: SVG converting issue resulting in DoS
A vulnerability was found in ImageMagick. Conversion of a circularly defined svg file could cause the application to go into infinite loop.
References:
http://seclists.org/oss-sec/2016/q2/182
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1333418]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q2/460
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1237 https://access.redhat.com/errata/RHSA-2016:1237
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=999653786df6954a31044528ac3f7a5dadca08f4http://www.debian.org/security/2016/dsa-3607http://www.openwall.com/lists/oss-security/2016/06/25/2http://www.securityfocus.com/bid/91456http://www.ubuntu.com/usn/USN-3053-1http://www.ubuntu.com/usn/USN-3070-1http://www.ubuntu.com/usn/USN-3070-2http://www.ubuntu.com/usn/USN-3070-3http://www.ubuntu.com/usn/USN-3070-4https://bugzilla.redhat.com/show_bug.cgi?id=1350845https://github.com/torvalds/linux/commit/999653786df6954a31044528ac3f7a5dadca08f4http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=999653786df6954a31044528ac3f7a5dadca08f4http://www.debian.org/security/2016/dsa-3607http://www.openwall.com/lists/oss-security/2016/06/25/2http://www.securityfocus.com/bid/91456http://www.ubuntu.com/usn/USN-3053-1http://www.ubuntu.com/usn/USN-3070-1http://www.ubuntu.com/usn/USN-3070-2http://www.ubuntu.com/usn/USN-3070-3http://www.ubuntu.com/usn/USN-3070-4https://bugzilla.redhat.com/show_bug.cgi?id=1350845https://github.com/torvalds/linux/commit/999653786df6954a31044528ac3f7a5dadca08f4
2016-06-29
Published