| Name | CVE-2015-8660 |
| Description | The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. |
| Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more) |
| NVD severity | high (attack range: local) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| linux (PTS) | wheezy | 3.2.78-1 | fixed |
| wheezy (security) | 3.2.81-1 | fixed | |
| jessie | 3.16.7-ckt25-2 | fixed | |
| jessie (security) | 3.16.7-ckt25-2+deb8u3 | fixed | |
| stretch, sid | 4.6.4-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| linux | source | (unstable) | 4.3.3-3 | high | ||
| linux | source | jessie | (not affected) | |||
| linux | source | wheezy | (not affected) | |||
| linux-2.6 | source | (unstable) | (not affected) |
[jessie] - linux <not-affected> (Vulnerable code not present)
[wheezy] - linux <not-affected> (Vulnerable code not present)
- linux-2.6 <not-affected> (Vulnerable code not present)
Upstream commit: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=acff81ec2c79492b180fade3c2894425cd35a545 (v4.4-rc4)
OverlayFS introduced in https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e9be9d5e76e34872f0c37d72e25bc27fe9e2c54c (v3.18-rc2)
http://www.openwall.com/lists/oss-security/2015/12/23/5