The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2010/06/11/3 | Mailing List Third Party Advisory |
http://lkml.org/lkml/2010/5/17/544 | Exploit Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2010/06/14/2 | Mailing List Third Party Advisory |
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=2f26afba |
Configurations
Information
Published : 2010-06-16 13:30
Updated : 2023-02-12 20:19
NVD link : CVE-2010-2071
Mitre link : CVE-2010-2071
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
linux
- linux_kernel