Bug 1632443 (CVE-2018-16597)

Summary: CVE-2018-16597 kernel: overlayfs file truncation without permissions
Product: [Other] Security Response Reporter: Pedro Sampaio <psampaio>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abhgupta, acaringi, airlied, bhu, blc, brdeoliv, bskeggs, dbaker, dhoward, dvlasenk, esammons, ewk, fhrbata, hdegoede, hkrzesin, hwkernel-mgr, iboverma, ichavero, itamar, jarodwilson, jforbes, jglisse, jkacur, john.j5live, jokerman, jonathan, josef, jross, jstancek, jwboyer, kernel-maint, kernel-mgr, labbott, lgoncalv, linville, matt, mchehab, mcressma, mjg59, mlangsdo, nmurray, plougher, rt-maint, rvrbovsk, steved, sthangav, trankin, vdronov, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
An issue was discovered in the Linux kernel where an incorrect access check in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-10-10 16:46:39 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1361590, 1632444, 1632445, 1638097, 1641718    
Bug Blocks: 1632446    

Description Pedro Sampaio 2018-09-24 20:05:55 UTC
An issue was discovered in the Linux kernel where an incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.

References:

https://bugzilla.suse.com/show_bug.cgi?id=1106512

An upstream patch:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0ca3d70e8d3cf81e2255a217f7ca402f5ed0862

Comment 1 Pedro Sampaio 2018-09-24 20:07:31 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1632445]

Comment 8 Vladis Dronov 2018-10-22 15:12:57 UTC
this was fixed in RHEL-7.3 by bz1361590 and by the errata:

https://access.redhat.com/errata/RHSA-2016:2574