An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/105394 | third party advisory vdb entry |
https://security.netapp.com/advisory/ntap-20190204-0001/ | third party advisory patch |
https://bugzilla.suse.com/show_bug.cgi?id=1106512 | patch third party advisory issue tracking |
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0ca3d70e8d3cf81e2255a217f7ca402f5ed0862 | third party advisory patch |
https://support.f5.com/csp/article/K22691834 | third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html | vendor advisory mailing list third party advisory |
https://seclists.org/bugtraq/2019/Jul/33 | mailing list |
http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html |