Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel 本地拒绝服务漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 3.x版本的VFS子系统中存在安全漏洞,该漏洞源于程序提供了一组不完整的setattr操作要求(确认删除扩展的特权属性)。本地攻击者可借助失败的系统调用利用该漏洞造成拒绝服务(性能失效)。
CVSS Information
N/A
Vulnerability Type
N/A