Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel Btrfs 竞争条件漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 3.18.8及之前版本的Btrfs实现过程中存在安全漏洞,该漏洞源于程序没有正确替换xattr(扩展属性)。本地攻击者可通过在xattr-replacement时间窗口存在期间或xattr-replacement请求失败时执行标准文件系统操作,利用该漏洞绕过既定的ACL设置,获取权限。
CVSS Information
N/A
Vulnerability Type
N/A