CVE-2014-8989

Public on 2014-11-30
Modified on 2015-02-11
Description
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.
Severity
Medium severity
Medium
CVSS v3 Base Score
3.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 kernel 2015-02-11 ALAS-2015-476 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 3.6 AV:L/AC:L/Au:N/C:P/I:P/A:N
NVD CVSSv2 4.6 AV:L/AC:L/Au:N/C:P/I:P/A:P