CVE-2015-1350

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1185139

http://www.openwall.com/lists/oss-security/2015/01/24/5

http://marc.info/?l=linux-kernel&m=142153722930533&w=2

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=770492

http://www.securityfocus.com/bid/76075

Details

Source: MITRE

Published: 2016-05-02

Updated: 2020-08-03

Type: CWE-552

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (14 total)

IDNameProductFamilySeverity
148498Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4904-1)NessusUbuntu Local Security Checks
medium
132360EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-2693)NessusHuawei Local Security Checks
high
132134EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2599)NessusHuawei Local Security Checks
high
131845EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-2353)NessusHuawei Local Security Checks
critical
124971EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1518)NessusHuawei Local Security Checks
high
101929Ubuntu 16.04 LTS : linux-hwe vulnerabilities (USN-3361-1)NessusUbuntu Local Security Checks
critical
100320SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:1360-1)NessusSuSE Local Security Checks
critical
100150SUSE SLES12 Security Update : kernel (SUSE-SU-2017:1247-1)NessusSuSE Local Security Checks
critical
97297SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0494-1)NessusSuSE Local Security Checks
critical
97097SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0437-1)NessusSuSE Local Security Checks
critical
96903SUSE SLES11 Security Update : kernel (SUSE-SU-2017:0333-1)NessusSuSE Local Security Checks
critical
96603SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:0181-1)NessusSuSE Local Security Checks
high
96188Debian DLA-772-1 : linux security updateNessusDebian Local Security Checks
critical
95701openSUSE Security Update : the Linux Kernel (openSUSE-2016-1426)NessusSuSE Local Security Checks
critical