Back to search
CVE-2015-5231
Published: Jun 7, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20150825 CVE-2015-5228 & CVE-2015-5231 in the criu service daemon
mailing-list
x_refsource_MLIST
openSUSE-SU-2015:1593
vendor-advisory
x_refsource_SUSE
[CRIU] 20150825 Hardening the criu service daemon
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=1256728
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now