Vulnerability Description
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 3.14.8 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=
- http://secunia.com/advisories/59220Third Party Advisory
- http://www.exploit-db.com/exploits/33824Third Party AdvisoryVDB Entry
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/06/10/4Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/67988Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030394Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1107966Issue TrackingThird Party Advisory
- https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd0Third Party Advisory
- https://source.android.com/security/bulletin/2016-12-01.htmlThird Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=
- http://secunia.com/advisories/59220Third Party Advisory
- http://www.exploit-db.com/exploits/33824Third Party AdvisoryVDB Entry
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/06/10/4Mailing ListThird Party Advisory
FAQ
What is CVE-2014-4014?
CVE-2014-4014 is a vulnerability with a CVSS score of 6.2 (MEDIUM). The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions ...
How severe is CVE-2014-4014?
CVE-2014-4014 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4014?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.