CVE-2016-1572: High severity ecryptfs-utils vulnerability
mount.ecryptfsprivate.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1572?
CVE-2016-1572 has been classified as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2016-1572?
To resolve CVE-2016-1572, update the eCryptfs-utils package to a version that is patched against this vulnerability.
Who is affected by CVE-2016-1572?
CVE-2016-1572 affects multiple versions of eCryptfs-utils across several Linux distributions, including Ubuntu, Debian, Fedora, and openSUSE.
What types of attacks can exploit CVE-2016-1572?
CVE-2016-1572 can be exploited by local users to gain elevated privileges by improperly mounting over nonstandard filesystem types.
What component of eCryptfs-utils is vulnerable in CVE-2016-1572?
The vulnerability in CVE-2016-1572 is found in the mount.ecryptfs_private.c component, which fails to validate mount destination filesystem types.