CVE-2015-1328
HIGH 7.8EPSS 37.7%
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.
- CVSS v3.0
- 7.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 37.68% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2016-11-28
- Updated
- 2024-08-06
Proof-of-concept exploits (12)
- http://www.exploit-db.com/exploits/40688/
- 0x1ns4n3/CVE-2015-1328-GoldenEye10★ · 2025-01-14
- SR7-HACKING/LINUX-VULNERABILITY-CVE-2015-13280★ · 2020-05-12
- YastrebX/CVE-2015-13280★ · 2024-11-12
- elit3pwner/CVE-2015-1328-GoldenEye10★ · 2025-01-14
- freelancermijan/Linux-Privilege-Escalation-Tryhackme0★ · 2023-05-10
- notlikethis/CVE-2015-13280★ · 2021-06-26
- 0xf1d0/CVE-2015-1328
- FernandoCassioDev/CVE-2015-1328
- WhatsWrongAndWhy/CVE-2015-1328
- bansalkrish007-arch/cve-2015-1328
- saqib-butt2/blackbox-pentesting-infsecos
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/40688
- https://www.exploit-db.com/exploits/37293
- https://www.exploit-db.com/exploits/37292