Hide Forgot
It was discovered that shiftfs, when passing through ioctls to the underlying file system, did not properly handle faults occurring during copy_from_user() correctly, leading to a double-free vulnerability or not freeing memory at all. An attacker could use this to cause a denial of service (memory consumption) or execute arbitrary code. References: https://www.openwall.com/lists/oss-security/2021/04/16/2
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1950503]
"Shiftfs is an out-of-tree stacking file system for the Linux kernel included in Ubuntu kernels" Fedora does not carry this patch set.
Statement: Shiftfs has not been accepted in the upstream Linux kernel. It is both non included to the any versions of the Red Hat Enterprise Linux.