CVE-2015-0274: High severity linux kernel vulnerability

Published Feb 23, 2015
·
Updated

A flaw was found in the way the Linux kernel's XFS file system handled replacing of remote attributes under certain conditions.

A local user with access to XFS file system mount could potentially use this flaw to escalate their privileges on the system.

Fixed by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59

Introduced by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e461fcb

Acknowledgements:

Red Hat would like to thank Eric Windisch of the Docker project for reporting this issue.

Other sources

The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.

Affected Software

5 affected componentsFixes available
redhat/kernel<0:3.10.0-229.el7
0:3.10.0-229.el7
redhat/kernel-rt<1:3.10.0-229.rt56.144.el6
1:3.10.0-229.rt56.144.el6
Linux Linux kernel>=3.11<3.15
Linux Linux kernel<=3.14.5
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Event History

Feb 23, 2015
Data Sourced
via Red Hat·01:31 PM
DescriptionSeverityAffected Software
Mar 5, 2015
CVE Published
12:00 AM
Mar 16, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:08 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:05 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·03:14 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2015-0274?

The severity of CVE-2015-0274 is considered high due to the potential for privilege escalation in the Linux kernel's XFS file system.

2

How do I fix CVE-2015-0274?

To fix CVE-2015-0274, update your Linux kernel to a version that includes the security patches addressing this vulnerability.

3

Who is affected by CVE-2015-0274?

CVE-2015-0274 affects local users with access to the XFS file system mount on vulnerable versions of the Linux kernel.

4

What versions of Linux Kernel are vulnerable to CVE-2015-0274?

Versions of the Linux Kernel from 3.11 to 3.14.5 are vulnerable to CVE-2015-0274.

5

How can CVE-2015-0274 impact my system?

CVE-2015-0274 can allow a local user to escalate their privileges, potentially leading to unauthorized access and control over the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203