Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux内核btrfs 'fs/btrfs/acl.c'btrfs_xattr_set_acl函数权限许可和访问控制问题漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux内核btrfs的fs/btrfs/acl.c的btrfs_xattr_set_acl函数,在设置ACL前无法检查文件所有权,本地用户可通过设置任意ACL,绕开文件权限,比如使用setfacl。
CVSS Information
N/A
Vulnerability Type
N/A