The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: canonical

Published: 2016-05-02T10:00:00

Updated: 2021-10-18T20:06:10

Reserved: 2016-01-12T00:00:00


Link: CVE-2016-1576

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2016-05-02T10:59:24.487

Modified: 2022-04-18T17:59:39.373


Link: CVE-2016-1576

JSON object: View

cve-icon Redhat Information

No data.