vendor:
Linux Kernel
by:
rebel
6,7
CVSS
MEDIUM
overlayfs
264
CWE
Product Name: Linux Kernel
Affected Version From: Ubuntu 14.04 LTS
Affected Version To: Ubuntu 15.10
Patch Exists: YES
Related CWE: CVE-2015-8660
CPE: o:linux:linux_kernel
Metasploit:
https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2015-8660/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2015-8660/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-8660/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2015-8660/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-8660/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2015-8660/, https://www.rapid7.com/db/modules/exploit/linux/local/overlayfs_priv_esc/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 14.04 LTS, 15.10
2016
overlayfs local root
This exploit allows a local user to gain root privileges on Ubuntu 14.04 LTS, 15.10 and more. It works by creating a new user namespace, a new mount namespace, and then mounting an overlayfs filesystem. The user then executes a shell with root privileges.
Mitigation:
Upgrade to a kernel version after 2015-12-26