Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2015-8660 PoC — Linux kernel‘fs/overlayfs/inode.c’权限许可和访问控制问题漏洞

Source
Associated Vulnerability
Title: Linux kernel‘fs/overlayfs/inode.c’权限许可和访问控制问题漏洞 (CVE-2015-8660)
Description:The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
Readme
<h1> CVE 2015-8660 Research</h1>


<h2>Description</h2>
This is research I conducted on the CVE 2015-8660 overlayFS vulnerability for my Operating System Security course final research project. The goal of this project was to find a Linux kernel vulnerability from 2012-2022, explain the vulnerability, explain the potential effects, and demonstrate the vulnerability using a crafted exploit. This vulnerability is caused by the ovl_setattr funtion located in the fs/overlayfs/inode.c program. When exploited via a crafted application, a malicious user will be able to gain privileged access to a loca machine. This vulnerability affects linux kernel versions through 4.3.3. My project research paper is included as well as a video of my demonstration using exploit code found on Exploit-db referenced below.
<br />


<h2>Tools Used</h2>

- <b> CVE Database </b>
- <b> Virtual Machines (Ubuntu 15.04)</b>



<h2>Environments Used </h2>

- <b> Ubuntu 15.04 </b>

<h2>References</h2>

- <b> [exploitdb](https://www.exploit-db.com/exploits/39166) </b>
- <b> [CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8660) </b>
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →