Ubuntu Shiftfs In The Linux Kernel vulnerabilities
3 known vulnerabilities affecting ubuntu/shiftfs_in_the_linux_kernel.
Total CVEs
3
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2019-15792HIGHCVSS 7.8PoC≥ 5.3.0-11.12, < 5.3 kernel*≥ 5.0 kernel, < 5.0.0-35.382020-04-24
CVE-2019-15792 [HIGH] CWE-843 CVE-2019-15792: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void* that points to a filesystem-dependent type, to a "struct shiftfs_file_info
cvelistv5nvd
CVE-2019-15791HIGHCVSS 7.8PoC≥ 5.3.0-11.12, < 5.3 kernel*≥ 5.0 kernel, < 5.0.0-35.382020-04-24
CVE-2019-15791 [HIGH] CWE-672 CVE-2019-15791: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a reference to that file, leading to
cvelistv5nvd
CVE-2019-15793HIGHCVSS 8.8PoC≥ 5.3.0-11.12, < 5.3 kernel*≥ 5.0 kernel, < 5.0.0-35.382020-04-24
CVE-2019-15793 [HIGH] CWE-538 CVE-2019-15793: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should have been translated into the s_user_ns for the lower filesystem. This result
cvelistv5nvd