Description
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-9517 | The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit. |
Ubuntu USN |
USN-2615-1 | Linux kernel (Utopic HWE) vulnerabilities |
Ubuntu USN |
USN-2616-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2662-1 | Linux kernel (Trusty HWE) vulnerabilities |
Ubuntu USN |
USN-2663-1 | Linux kernel vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T13:55:04.048Z
Reserved: 2015-03-24T00:00:00.000Z
Link: CVE-2014-9710
No data.
Status : Modified
Published: 2015-05-27T10:59:00.063
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-9710
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN