cbcvebase.
CVE-2016-1572
published 2016-01-22

CVE-2016-1572: mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a…

PriorityP339high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.37%
29.1th percentile
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianecryptfs-utils< ecryptfs-utils 106-2 (bookworm)ecryptfs-utils 106-2 (bookworm)
ecryptfsecryptfs-utils< 109109
ecryptfsecryptfs-utils>= 0 < 106-2106-2
ecryptfsecryptfs-utils>= 0 < 106-2106-2
ecryptfsecryptfs-utils>= 0 < 106-2106-2
ecryptfsecryptfs-utils>= 0 < 106-2106-2
ecryptfsecryptfs-utils>= 0 < 104-0ubuntu1.14.04.4104-0ubuntu1.14.04.4
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
vendor_ubuntu8.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.