Bug 1185139 (CVE-2015-1350)
Summary: | CVE-2015-1350 kernel: denial of service in notify_change for filesystem xattrs | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Wade Mealing <wmealing> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | agordeev, aquini, carnil, dhoward, fhrbata, gansalmon, itamar, jforbes, jonathan, jwboyer, kernel-maint, kernel-mgr, lwang, madhu.chinakonda, mchehab, mguzik, nmurray, pholasek, plougher, pmatouse, rvrbovsk |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
It was found that a regular user could remove xattr permissions on files by using the chown or write system calls. A local attacker could use this flaw to deny elevated permissions from valid users, services, or applications, potentially resulting in a denial of service.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2015-11-02 15:33:35 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1185142, 1185143, 1185144, 1185145, 1186117, 1192874, 1195677, 1195678, 1195679 | ||
Bug Blocks: | 1167369 |
Description
Wade Mealing
2015-01-23 04:53:23 UTC
Statement: This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, 7 and MRG 2. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1192874] |