Comment 1 for bug 1873074

Revision history for this message
Mauricio Faria de Oliveira (mfo) wrote :

Security Impact:
---

The root cause of this problem can be easily exploited
by unprivileged users, both local and remote attackers.

It only needs access to an aufs mount point with read
permissions to any file; opening it in read-only mode,
repeatedly.

For that reason, probably sending the patch for this,
even if keeping it low profile and boring on wording,
may reveal enough information to exploit the problem,
and probably needs some care taking and coordination.

Details in 'Exploit / Local' (and Remote) sections.