The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=2f26afba | |
http://lkml.org/lkml/2010/5/17/544 | mailing list exploit third party advisory patch |
http://www.openwall.com/lists/oss-security/2010/06/14/2 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2010/06/11/3 | third party advisory mailing list |