CVE-2015-8709

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

** DISPUTED ** kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here."

References

http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.html

http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.html

http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html

http://marc.info/?l=linux-kernel&m=145204362722256&w=2

http://marc.info/?l=linux-kernel&m=145204641422813&w=2

http://www.debian.org/security/2016/dsa-3434

http://www.openwall.com/lists/oss-security/2015/12/17/12

http://www.openwall.com/lists/oss-security/2015/12/31/5

http://www.securityfocus.com/bid/79899

http://www.securitytracker.com/id/1034899

https://bugzilla.redhat.com/show_bug.cgi?id=1295287

https://lkml.org/lkml/2015/12/25/71

Details

Source: MITRE

Published: 2016-02-08

Updated: 2017-11-04

Type: CWE-264

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.4.1 (inclusive)

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
124976EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1523)NessusHuawei Local Security Checks
critical
97466SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:0575-1)NessusSuSE Local Security Checks
critical
97274openSUSE Security Update : the Linux Kernel (openSUSE-2017-245)NessusSuSE Local Security Checks
critical
93104openSUSE Security Update : the Linux Kernel (openSUSE-2016-1015)NessusSuSE Local Security Checks
critical
90783openSUSE Security Update : the Linux Kernel (openSUSE-2016-518)NessusSuSE Local Security Checks
critical
90531SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2016:1019-1)NessusSuSE Local Security Checks
critical
90482openSUSE Security Update : the Linux Kernel (openSUSE-2016-445)NessusSuSE Local Security Checks
critical
89993SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2016:0785-1)NessusSuSE Local Security Checks
critical
89563Fedora 23 : kernel-4.3.3-300.fc23 (2016-6ce812a1e0)NessusFedora Local Security Checks
high
89554Fedora 22 : kernel-4.3.4-200.fc22 (2016-5d43766e33)NessusFedora Local Security Checks
critical
88660Amazon Linux AMI : kernel (ALAS-2016-648)NessusAmazon Linux Local Security Checks
high
87741Debian DSA-3434-1 : linux - security updateNessusDebian Local Security Checks
high