Back to search
CVE-2014-5206
Published: Aug 18, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox protection mechanisms via a "mount -o remount" command within a user namespace.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-2318-1
vendor-advisory
x_refsource_UBUNTU
69214
vdb-entry
x_refsource_BID
https://bugzilla.redhat.com/show_bug.cgi?id=1129662
x_refsource_CONFIRM
[oss-security] 20140813 Re: CVE Request: ro bind mount bypass using user namespaces
mailing-list
x_refsource_MLIST
USN-2317-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now