CVE Database
/

CVE-2015-8709

Back to search

CVE-2015-8709

Published: Feb 8, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2016:1038
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1033
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1034
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1035
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1764
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1031
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1019
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1037
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1045
vendor-advisory
x_refsource_SUSE
FEDORA-2016-5d43766e33
vendor-advisory
x_refsource_FEDORA
SUSE-SU-2016:1032
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1039
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1041
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:1046
vendor-advisory
x_refsource_SUSE
79899
vdb-entry
x_refsource_BID
1034899
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2016:1008
vendor-advisory
x_refsource_SUSE
DSA-3434
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2016:1040
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now