CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.
- Affected products
- Alt Linux, Linux Kernel, Ubuntu
- Canonical Ubuntu Linux
- ≤ 15.04
- Fix
- Available
- CVSS 3.0
- 7.8 HIGH
- EPSS
- 37.7% (98th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2016-11-28
CVE-2015-1328 at NVD
24 known exploits for CVE-2015-1328
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for CVE-2015-1328
Exploit for CVE-2015-1328
linux-privesc-linpeas
Exploit for CVE-2015-1328
Exploit for CVE-2015-1328
Exploit for CVE-2015-1328
Exploit for CVE-2015-1328
Kernelpop - Kernel Privilege Escalation Enumeration And Exploitation Framework
Immunity Canvas: OVERLAYFS
Linux Kernel (Ubuntu / Fedora / Redhat) - 'Overlayfs' Privilege Escalation Exploit
Overlayfs Privilege Escalation Exploit
Linux Kernel (Ubuntu / Fedora / RedHat) - 'Overlayfs' Local Privilege Escalation (Metasploit)
Overlayfs Privilege Escalation
Overlayfs Privilege Escalation
Ubuntu overlayfs privilege elevation
Ubuntu overlayfs privilege elevation
Ubuntu overlayfs privilege elevation
Ubuntu overlayfs privilege elevation
Ubuntu 12.04 / 14.04 / 14.10 / 15.04 overlayfs Local Root Exploit
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
Linux Kernel 3.13.0 3.19 (Ubuntu 12.0414.0414.1015.04) - overlayfs Local Privilege Escalation (Access etcshadow)
Linux Kernel 3.13.0 3.19 (Ubuntu 12.0414.0414.1015.04) - overlayfs Local Privilege Escalation
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
Ubuntu 12.04 / 14.04 / 14.10 / 15.04 overlayfs Local Root