CVE-2015-0274: High severity linux kernel vulnerability
A flaw was found in the way the Linux kernel's XFS file system handled replacing of remote attributes under certain conditions.
A local user with access to XFS file system mount could potentially use this flaw to escalate their privileges on the system.
Fixed by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59
Introduced by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e461fcb
Acknowledgements:
Red Hat would like to thank Eric Windisch of the Docker project for reporting this issue.
Other sources
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2015-0274?
The severity of CVE-2015-0274 is considered high due to the potential for privilege escalation in the Linux kernel's XFS file system.
How do I fix CVE-2015-0274?
To fix CVE-2015-0274, update your Linux kernel to a version that includes the security patches addressing this vulnerability.
Who is affected by CVE-2015-0274?
CVE-2015-0274 affects local users with access to the XFS file system mount on vulnerable versions of the Linux kernel.
What versions of Linux Kernel are vulnerable to CVE-2015-0274?
Versions of the Linux Kernel from 3.11 to 3.14.5 are vulnerable to CVE-2015-0274.
How can CVE-2015-0274 impact my system?
CVE-2015-0274 can allow a local user to escalate their privileges, potentially leading to unauthorized access and control over the system.