← All CVEs

CVE-2015-1328

high · 7.8

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

7.8
CVSS
37.7%
EPSS (exploit prob.)
98th
EPSS percentile
2016-11-28
Published

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
canonicalubuntu_linux<= 15.04
linuxlinux_kernel<= 3.19

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-1328