fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.
References
Configurations
Information
Published : 2016-05-02 03:59
Updated : 2016-05-05 10:01
NVD link : CVE-2015-4176
Mitre link : CVE-2015-4176
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
linux
- linux_kernel