PoC Index

CVE-2016-1576

HIGH 7.8EPSS 1.1%

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
1.13% chance of exploitation in the next 30 days, 64th percentile
Published
2016-05-02
Updated
2024-08-05

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related