CVE-2014-9922: Critical severity Linux Linux Kernel vulnerability
Published Apr 3, 2017
·Updated
The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c.
Affected Software
3 affected components
Linux Linux Kernel<=3.17.8
Google Android<=7.1.1
Google Android
Remediation
Patch Available
Event History
Apr 3, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Apr 4, 2017
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
Description
Frequently Asked Questions
1
Who is exposed to this issue?
Systems running Linux kernel versions before 3.18 are affected when they use an eCryptfs filesystem in a large filesystem stack that includes overlayfs. The listed software includes Google Android and the Linux kernel.
2
What level of access does an attacker need?
Exploitation is local. The CVSS vector indicates no privileges are required, but user interaction is required.
3
What is the recommended remediation?
Apply the available patch. The referenced upstream Linux kernel commit and Android security bulletin provide the associated remediation information.