CVEs Blog | G5 Cyber Security

CVE-2015-1350 – The VFS subsystem in the Linux kernel 3.x provides an incomplete set of r

The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1350

Reference (s):

Exit mobile version