Activity log for bug #1528904

Date Who What changed Old value New value Message
2015-12-23 17:24:44 Serge Hallyn bug added bug
2015-12-23 17:28:55 Serge Hallyn bug added subscriber Andy Whitcroft
2015-12-23 17:29:39 Serge Hallyn bug added subscriber Kamal Mostafa
2015-12-23 17:32:38 Serge Hallyn bug added subscriber Canonical Kernel Distro Team
2015-12-24 18:05:57 Tyler Hicks summary overlay getattr vulnerability overlay setattr vulnerability
2015-12-24 18:06:16 Launchpad Janitor linux (Ubuntu): status New Confirmed
2015-12-24 18:06:36 Tyler Hicks cve linked 2015-8660
2015-12-24 18:09:08 Tyler Hicks information type Private Security Public Security
2015-12-24 18:19:39 Tyler Hicks linux (Ubuntu): status Confirmed Triaged
2015-12-24 18:19:40 Tyler Hicks linux (Ubuntu): importance Undecided High
2015-12-31 19:26:49 Steve Beattie description http://www.openwall.com/lists/oss-security/2015/12/23/5 https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=acff81ec2c79492b180fade3c2894425cd35a545 This allows unprivileged users to change attributes on root-owned files. The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
2016-01-04 23:03:14 Steve Beattie nominated for series Ubuntu Wily
2016-01-04 23:03:14 Steve Beattie bug task added linux (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-ti-omap4 (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-armadaxp (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-quantal (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-raring (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-saucy (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-mako (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-manta (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-goldfish (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-flo (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-trusty (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-utopic (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-vivid (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-wily (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie bug task added linux-raspi2 (Ubuntu Wily)
2016-01-04 23:03:14 Steve Beattie nominated for series Ubuntu Vivid
2016-01-04 23:03:14 Steve Beattie bug task added linux (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-ti-omap4 (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-armadaxp (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-quantal (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-raring (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-saucy (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-mako (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-manta (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-goldfish (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-flo (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-trusty (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-utopic (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-vivid (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-lts-wily (Ubuntu Vivid)
2016-01-04 23:03:14 Steve Beattie bug task added linux-raspi2 (Ubuntu Vivid)
2016-01-04 23:03:32 Steve Beattie nominated for series Ubuntu Precise
2016-01-04 23:03:33 Steve Beattie bug task added linux (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-ti-omap4 (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-armadaxp (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-lts-quantal (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-lts-raring (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-lts-saucy (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-mako (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-manta (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-goldfish (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-flo (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-lts-trusty (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-lts-utopic (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-lts-vivid (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-lts-wily (Ubuntu Precise)
2016-01-04 23:03:33 Steve Beattie bug task added linux-raspi2 (Ubuntu Precise)
2016-01-04 23:03:37 Steve Beattie nominated for series Ubuntu Trusty
2016-01-04 23:03:38 Steve Beattie bug task added linux (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-ti-omap4 (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-armadaxp (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-lts-quantal (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-lts-raring (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-lts-saucy (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-mako (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-manta (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-goldfish (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-flo (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-lts-trusty (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-lts-utopic (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-lts-vivid (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-lts-wily (Ubuntu Trusty)
2016-01-04 23:03:38 Steve Beattie bug task added linux-raspi2 (Ubuntu Trusty)
2016-01-04 23:03:42 Steve Beattie nominated for series Ubuntu Xenial
2016-01-04 23:03:43 Steve Beattie bug task added linux (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-ti-omap4 (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-armadaxp (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-lts-quantal (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-lts-raring (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-lts-saucy (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-mako (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-manta (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-goldfish (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-flo (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-lts-trusty (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-lts-utopic (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-lts-vivid (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-lts-wily (Ubuntu Xenial)
2016-01-04 23:03:43 Steve Beattie bug task added linux-raspi2 (Ubuntu Xenial)
2016-01-04 23:03:49 Steve Beattie linux-lts-trusty (Ubuntu Precise): importance Undecided High
2016-01-04 23:03:51 Steve Beattie linux-lts-trusty (Ubuntu Wily): status New Invalid
2016-01-04 23:03:53 Steve Beattie linux-lts-trusty (Ubuntu Wily): importance Undecided High
2016-01-04 23:03:56 Steve Beattie linux-lts-trusty (Ubuntu Xenial): status New Invalid
2016-01-04 23:03:59 Steve Beattie linux-lts-trusty (Ubuntu Xenial): importance Undecided High
2016-01-04 23:04:01 Steve Beattie linux-lts-trusty (Ubuntu Trusty): status New Invalid
2016-01-04 23:04:03 Steve Beattie linux-lts-trusty (Ubuntu Trusty): importance Undecided High
2016-01-04 23:04:06 Steve Beattie linux-lts-trusty (Ubuntu Vivid): status New Invalid
2016-01-04 23:04:09 Steve Beattie linux-lts-trusty (Ubuntu Vivid): importance Undecided High
2016-01-04 23:04:11 Steve Beattie linux-lts-wily (Ubuntu Precise): status New Invalid
2016-01-04 23:04:14 Steve Beattie linux-lts-wily (Ubuntu Precise): importance Undecided High
2016-01-04 23:04:16 Steve Beattie linux-lts-wily (Ubuntu Wily): status New Invalid
2016-01-04 23:04:19 Steve Beattie linux-lts-wily (Ubuntu Wily): importance Undecided High
2016-01-04 23:04:21 Steve Beattie linux-lts-wily (Ubuntu Xenial): status New Invalid
2016-01-04 23:04:24 Steve Beattie linux-lts-wily (Ubuntu Xenial): importance Undecided High
2016-01-04 23:04:28 Steve Beattie linux-lts-wily (Ubuntu Trusty): status New Fix Committed
2016-01-04 23:04:31 Steve Beattie linux-lts-wily (Ubuntu Trusty): importance Undecided High
2016-01-04 23:04:32 Steve Beattie linux-lts-wily (Ubuntu Vivid): status New Invalid
2016-01-04 23:04:35 Steve Beattie linux-lts-wily (Ubuntu Vivid): importance Undecided High
2016-01-04 23:04:37 Steve Beattie linux-lts-quantal (Ubuntu Precise): status New Invalid
2016-01-04 23:04:39 Steve Beattie linux-lts-quantal (Ubuntu Precise): importance Undecided High
2016-01-04 23:04:42 Steve Beattie linux-lts-quantal (Ubuntu Wily): status New Invalid
2016-01-04 23:04:45 Steve Beattie linux-lts-quantal (Ubuntu Wily): importance Undecided High
2016-01-04 23:04:48 Steve Beattie linux-lts-quantal (Ubuntu Xenial): status New Invalid
2016-01-04 23:04:51 Steve Beattie linux-lts-quantal (Ubuntu Xenial): importance Undecided High
2016-01-04 23:04:54 Steve Beattie linux-lts-quantal (Ubuntu Trusty): status New Invalid
2016-01-04 23:04:57 Steve Beattie linux-lts-quantal (Ubuntu Trusty): importance Undecided High
2016-01-04 23:04:59 Steve Beattie linux-lts-quantal (Ubuntu Vivid): status New Invalid
2016-01-04 23:05:03 Steve Beattie linux-lts-quantal (Ubuntu Vivid): importance Undecided High
2016-01-04 23:05:05 Steve Beattie linux (Ubuntu Precise): importance Undecided High
2016-01-04 23:05:08 Steve Beattie linux (Ubuntu Wily): status New Fix Committed
2016-01-04 23:05:10 Steve Beattie linux (Ubuntu Wily): importance Undecided High
2016-01-04 23:05:12 Steve Beattie linux (Ubuntu Xenial): status Triaged Fix Committed
2016-01-04 23:05:14 Steve Beattie linux (Ubuntu Trusty): importance Undecided High
2016-01-04 23:05:16 Steve Beattie linux (Ubuntu Vivid): status New Fix Committed
2016-01-04 23:05:18 Steve Beattie linux (Ubuntu Vivid): importance Undecided High
2016-01-04 23:05:21 Steve Beattie linux-ti-omap4 (Ubuntu Precise): importance Undecided High
2016-01-04 23:05:24 Steve Beattie linux-ti-omap4 (Ubuntu Wily): status New Invalid
2016-01-04 23:05:27 Steve Beattie linux-ti-omap4 (Ubuntu Wily): importance Undecided High
2016-01-04 23:05:29 Steve Beattie linux-ti-omap4 (Ubuntu Xenial): status New Invalid
2016-01-04 23:05:33 Steve Beattie linux-ti-omap4 (Ubuntu Xenial): importance Undecided High
2016-01-04 23:05:35 Steve Beattie linux-ti-omap4 (Ubuntu Trusty): status New Invalid
2016-01-04 23:05:39 Steve Beattie linux-ti-omap4 (Ubuntu Trusty): importance Undecided High
2016-01-04 23:05:41 Steve Beattie linux-ti-omap4 (Ubuntu Vivid): status New Invalid
2016-01-04 23:05:44 Steve Beattie linux-ti-omap4 (Ubuntu Vivid): importance Undecided High
2016-01-04 23:05:46 Steve Beattie linux-lts-raring (Ubuntu Precise): status New Invalid
2016-01-04 23:05:49 Steve Beattie linux-lts-raring (Ubuntu Precise): importance Undecided High
2016-01-04 23:05:51 Steve Beattie linux-lts-raring (Ubuntu Wily): status New Invalid
2016-01-04 23:05:54 Steve Beattie linux-lts-raring (Ubuntu Wily): importance Undecided High
2016-01-04 23:05:55 Steve Beattie linux-lts-raring (Ubuntu Xenial): status New Invalid
2016-01-04 23:05:58 Steve Beattie linux-lts-raring (Ubuntu Xenial): importance Undecided High
2016-01-04 23:06:00 Steve Beattie linux-lts-raring (Ubuntu Trusty): status New Invalid
2016-01-04 23:06:03 Steve Beattie linux-lts-raring (Ubuntu Trusty): importance Undecided High
2016-01-04 23:06:05 Steve Beattie linux-lts-raring (Ubuntu Vivid): status New Invalid
2016-01-04 23:06:09 Steve Beattie linux-lts-raring (Ubuntu Vivid): importance Undecided High
2016-01-04 23:06:11 Steve Beattie linux-armadaxp (Ubuntu Precise): importance Undecided High
2016-01-04 23:06:13 Steve Beattie linux-armadaxp (Ubuntu Wily): status New Invalid
2016-01-04 23:06:15 Steve Beattie linux-armadaxp (Ubuntu Wily): importance Undecided High
2016-01-04 23:06:17 Steve Beattie linux-armadaxp (Ubuntu Xenial): status New Invalid
2016-01-04 23:06:20 Steve Beattie linux-armadaxp (Ubuntu Xenial): importance Undecided High
2016-01-04 23:06:22 Steve Beattie linux-armadaxp (Ubuntu Trusty): status New Invalid
2016-01-04 23:06:25 Steve Beattie linux-armadaxp (Ubuntu Trusty): importance Undecided High
2016-01-04 23:06:28 Steve Beattie linux-armadaxp (Ubuntu Vivid): status New Invalid
2016-01-04 23:06:32 Steve Beattie linux-armadaxp (Ubuntu Vivid): importance Undecided High
2016-01-04 23:06:34 Steve Beattie linux-lts-saucy (Ubuntu Precise): status New Invalid
2016-01-04 23:06:37 Steve Beattie linux-lts-saucy (Ubuntu Precise): importance Undecided High
2016-01-04 23:06:39 Steve Beattie linux-lts-saucy (Ubuntu Wily): status New Invalid
2016-01-04 23:06:42 Steve Beattie linux-lts-saucy (Ubuntu Wily): importance Undecided High
2016-01-04 23:06:45 Steve Beattie linux-lts-saucy (Ubuntu Xenial): status New Invalid
2016-01-04 23:06:48 Steve Beattie linux-lts-saucy (Ubuntu Xenial): importance Undecided High
2016-01-04 23:06:51 Steve Beattie linux-lts-saucy (Ubuntu Trusty): status New Invalid
2016-01-04 23:06:53 Steve Beattie linux-lts-saucy (Ubuntu Trusty): importance Undecided High
2016-01-04 23:06:55 Steve Beattie linux-lts-saucy (Ubuntu Vivid): status New Invalid
2016-01-04 23:06:58 Steve Beattie linux-lts-saucy (Ubuntu Vivid): importance Undecided High
2016-01-04 23:07:00 Steve Beattie linux-manta (Ubuntu Precise): status New Invalid
2016-01-04 23:07:02 Steve Beattie linux-manta (Ubuntu Precise): importance Undecided High
2016-01-04 23:07:05 Steve Beattie linux-manta (Ubuntu Wily): importance Undecided High
2016-01-04 23:07:07 Steve Beattie linux-manta (Ubuntu Xenial): importance Undecided High
2016-01-04 23:07:09 Steve Beattie linux-manta (Ubuntu Trusty): status New Invalid
2016-01-04 23:07:12 Steve Beattie linux-manta (Ubuntu Trusty): importance Undecided High
2016-01-04 23:07:14 Steve Beattie linux-manta (Ubuntu Vivid): importance Undecided High
2016-01-04 23:07:16 Steve Beattie linux-lts-vivid (Ubuntu Precise): status New Invalid
2016-01-04 23:07:19 Steve Beattie linux-lts-vivid (Ubuntu Precise): importance Undecided High
2016-01-04 23:07:21 Steve Beattie linux-lts-vivid (Ubuntu Wily): status New Invalid
2016-01-04 23:07:23 Steve Beattie linux-lts-vivid (Ubuntu Wily): importance Undecided High
2016-01-04 23:07:25 Steve Beattie linux-lts-vivid (Ubuntu Xenial): status New Invalid
2016-01-04 23:07:28 Steve Beattie linux-lts-vivid (Ubuntu Xenial): importance Undecided High
2016-01-04 23:07:29 Steve Beattie linux-lts-vivid (Ubuntu Trusty): status New Fix Committed
2016-01-04 23:07:32 Steve Beattie linux-lts-vivid (Ubuntu Trusty): importance Undecided High
2016-01-04 23:07:35 Steve Beattie linux-lts-vivid (Ubuntu Vivid): status New Invalid
2016-01-04 23:07:39 Steve Beattie linux-lts-vivid (Ubuntu Vivid): importance Undecided High
2016-01-04 23:07:40 Steve Beattie linux-raspi2 (Ubuntu Precise): status New Invalid
2016-01-04 23:07:44 Steve Beattie linux-raspi2 (Ubuntu Precise): importance Undecided High
2016-01-04 23:07:46 Steve Beattie linux-raspi2 (Ubuntu Wily): status New Fix Committed
2016-01-04 23:07:48 Steve Beattie linux-raspi2 (Ubuntu Wily): importance Undecided High
2016-01-04 23:07:51 Steve Beattie linux-raspi2 (Ubuntu Xenial): importance Undecided High
2016-01-04 23:07:53 Steve Beattie linux-raspi2 (Ubuntu Trusty): status New Invalid
2016-01-04 23:07:56 Steve Beattie linux-raspi2 (Ubuntu Trusty): importance Undecided High
2016-01-04 23:07:58 Steve Beattie linux-raspi2 (Ubuntu Vivid): status New Invalid
2016-01-04 23:08:00 Steve Beattie linux-raspi2 (Ubuntu Vivid): importance Undecided High
2016-01-04 23:08:03 Steve Beattie linux-mako (Ubuntu Precise): status New Invalid
2016-01-04 23:08:06 Steve Beattie linux-mako (Ubuntu Precise): importance Undecided High
2016-01-04 23:08:09 Steve Beattie linux-mako (Ubuntu Wily): importance Undecided High
2016-01-04 23:08:11 Steve Beattie linux-mako (Ubuntu Xenial): importance Undecided High
2016-01-04 23:08:14 Steve Beattie linux-mako (Ubuntu Trusty): status New Invalid
2016-01-04 23:08:17 Steve Beattie linux-mako (Ubuntu Trusty): importance Undecided High
2016-01-04 23:08:20 Steve Beattie linux-mako (Ubuntu Vivid): importance Undecided High
2016-01-04 23:08:22 Steve Beattie linux-lts-utopic (Ubuntu Precise): status New Invalid
2016-01-04 23:08:25 Steve Beattie linux-lts-utopic (Ubuntu Precise): importance Undecided High
2016-01-04 23:08:26 Steve Beattie linux-lts-utopic (Ubuntu Wily): status New Invalid
2016-01-04 23:08:29 Steve Beattie linux-lts-utopic (Ubuntu Wily): importance Undecided High
2016-01-04 23:08:30 Steve Beattie linux-lts-utopic (Ubuntu Xenial): status New Invalid
2016-01-04 23:08:33 Steve Beattie linux-lts-utopic (Ubuntu Xenial): importance Undecided High
2016-01-04 23:08:36 Steve Beattie linux-lts-utopic (Ubuntu Trusty): importance Undecided High
2016-01-04 23:08:39 Steve Beattie linux-lts-utopic (Ubuntu Vivid): status New Invalid
2016-01-04 23:08:41 Steve Beattie linux-lts-utopic (Ubuntu Vivid): importance Undecided High
2016-01-04 23:08:44 Steve Beattie linux-goldfish (Ubuntu Precise): status New Invalid
2016-01-04 23:08:47 Steve Beattie linux-goldfish (Ubuntu Precise): importance Undecided High
2016-01-04 23:08:50 Steve Beattie linux-goldfish (Ubuntu Wily): importance Undecided High
2016-01-04 23:08:52 Steve Beattie linux-goldfish (Ubuntu Xenial): importance Undecided High
2016-01-04 23:08:54 Steve Beattie linux-goldfish (Ubuntu Trusty): status New Invalid
2016-01-04 23:08:57 Steve Beattie linux-goldfish (Ubuntu Trusty): importance Undecided High
2016-01-04 23:08:59 Steve Beattie linux-goldfish (Ubuntu Vivid): importance Undecided High
2016-01-04 23:09:01 Steve Beattie linux-flo (Ubuntu Precise): status New Invalid
2016-01-04 23:09:04 Steve Beattie linux-flo (Ubuntu Precise): importance Undecided High
2016-01-04 23:09:07 Steve Beattie linux-flo (Ubuntu Wily): importance Undecided High
2016-01-04 23:09:09 Steve Beattie linux-flo (Ubuntu Xenial): importance Undecided High
2016-01-04 23:09:11 Steve Beattie linux-flo (Ubuntu Trusty): status New Invalid
2016-01-04 23:09:13 Steve Beattie linux-flo (Ubuntu Trusty): importance Undecided High
2016-01-04 23:09:15 Steve Beattie linux-flo (Ubuntu Vivid): importance Undecided High
2016-01-04 23:09:17 Steve Beattie description The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. Break-Fix: - acff81ec2c79492b180fade3c2894425cd35a545
2016-01-05 14:38:10 Launchpad Janitor linux (Ubuntu Wily): status Fix Committed Fix Released
2016-01-05 14:38:10 Launchpad Janitor linux (Ubuntu Wily): status Fix Committed Fix Released
2016-01-05 14:42:27 Launchpad Janitor linux (Ubuntu Vivid): status Fix Committed Fix Released
2016-01-05 14:43:17 Launchpad Janitor linux-lts-vivid (Ubuntu Trusty): status Fix Committed Fix Released
2016-01-05 14:44:48 Launchpad Janitor linux-raspi2 (Ubuntu Wily): status Fix Committed Fix Released
2016-01-05 14:44:49 Launchpad Janitor linux-raspi2 (Ubuntu Wily): status Fix Committed Fix Released
2016-01-05 14:45:19 Launchpad Janitor linux-lts-wily (Ubuntu Trusty): status Fix Committed Fix Released
2016-01-05 14:45:20 Launchpad Janitor linux-lts-wily (Ubuntu Trusty): status Fix Committed Fix Released
2016-01-06 02:06:22 Mathew Hodson tags kernel-cve-tracking-bug
2016-01-06 02:08:12 Mathew Hodson summary overlay setattr vulnerability 2015-8660
2016-01-06 02:08:27 Mathew Hodson summary 2015-8660 CVE-2015-8660
2016-01-19 15:21:14 Launchpad Janitor linux (Ubuntu Xenial): status Fix Committed Fix Released
2016-02-10 21:39:26 Steve Beattie linux-raspi2 (Ubuntu Xenial): status New Fix Committed
2016-02-11 00:30:59 Steve Beattie linux-lts-xenial (Ubuntu Precise): status New Invalid
2016-02-11 00:31:02 Steve Beattie linux-lts-xenial (Ubuntu Precise): importance Undecided High
2016-02-11 00:31:05 Steve Beattie linux-lts-xenial (Ubuntu Wily): status New Invalid
2016-02-11 00:31:09 Steve Beattie linux-lts-xenial (Ubuntu Wily): importance Undecided High
2016-02-11 00:31:13 Steve Beattie linux-lts-xenial (Ubuntu Xenial): status New Invalid
2016-02-11 00:31:17 Steve Beattie linux-lts-xenial (Ubuntu Xenial): importance Undecided High
2016-02-11 00:31:19 Steve Beattie linux-lts-xenial (Ubuntu Trusty): status New Fix Committed
2016-02-11 00:31:22 Steve Beattie linux-lts-xenial (Ubuntu Trusty): importance Undecided High
2016-02-24 12:42:53 Launchpad Janitor branch linked lp:ubuntu/trusty-security/linux-lts-vivid
2016-02-24 12:44:17 Launchpad Janitor branch linked lp:ubuntu/trusty-proposed/linux-lts-vivid
2016-02-24 13:04:36 Launchpad Janitor branch linked lp:~ubuntu-branches/ubuntu/trusty/linux-lts-wily/trusty-security
2016-02-24 13:07:51 Launchpad Janitor branch linked lp:~ubuntu-branches/ubuntu/trusty/linux-lts-wily/trusty-proposed
2016-04-19 10:24:54 Steve Beattie linux-manta (Ubuntu Xenial): status New Invalid
2016-04-27 17:03:31 Steve Beattie nominated for series Ubuntu Yakkety
2016-04-27 17:03:32 Steve Beattie bug task added linux (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-ti-omap4 (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-armadaxp (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-quantal (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-raring (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-saucy (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-mako (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-manta (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-goldfish (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-flo (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-trusty (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-utopic (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-vivid (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-wily (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-raspi2 (Ubuntu Yakkety)
2016-04-27 17:03:32 Steve Beattie bug task added linux-lts-xenial (Ubuntu Yakkety)
2016-04-27 18:36:54 Steve Beattie description The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. Break-Fix: - acff81ec2c79492b180fade3c2894425cd35a545 The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. Break-Fix: e9be9d5e76e34872f0c37d72e25bc27fe9e2c54c acff81ec2c79492b180fade3c2894425cd35a545
2016-04-27 22:14:14 Steve Beattie linux-lts-trusty (Ubuntu Precise): status New Invalid
2016-04-27 22:14:20 Steve Beattie linux (Ubuntu Precise): status New Invalid
2016-04-27 22:14:24 Steve Beattie linux (Ubuntu Trusty): status New Invalid
2016-04-27 22:14:28 Steve Beattie linux-ti-omap4 (Ubuntu Precise): status New Invalid
2016-04-27 22:14:32 Steve Beattie linux-armadaxp (Ubuntu Precise): status New Invalid
2016-04-27 22:14:35 Steve Beattie linux-lts-utopic (Ubuntu Trusty): status New Invalid
2016-05-06 00:14:55 Steve Beattie linux-snapdragon (Ubuntu Precise): status New Invalid
2016-05-06 00:14:59 Steve Beattie linux-snapdragon (Ubuntu Precise): importance Undecided High
2016-05-06 00:15:03 Steve Beattie linux-snapdragon (Ubuntu Wily): status New Invalid
2016-05-06 00:15:07 Steve Beattie linux-snapdragon (Ubuntu Wily): importance Undecided High
2016-05-06 00:15:10 Steve Beattie linux-snapdragon (Ubuntu Xenial): status New Invalid
2016-05-06 00:15:14 Steve Beattie linux-snapdragon (Ubuntu Xenial): importance Undecided High
2016-05-06 00:15:16 Steve Beattie linux-snapdragon (Ubuntu Yakkety): status New Invalid
2016-05-06 00:15:20 Steve Beattie linux-snapdragon (Ubuntu Yakkety): importance Undecided High
2016-05-06 00:15:23 Steve Beattie linux-snapdragon (Ubuntu Trusty): status New Invalid
2016-05-06 00:15:26 Steve Beattie linux-snapdragon (Ubuntu Trusty): importance Undecided High
2017-10-17 15:11:44 Andy Whitcroft linux-flo (Ubuntu Vivid): status New Won't Fix
2017-10-17 15:57:56 Andy Whitcroft linux-goldfish (Ubuntu Vivid): status New Won't Fix
2017-10-17 17:17:19 Andy Whitcroft linux-mako (Ubuntu Vivid): status New Won't Fix
2017-10-17 17:41:35 Andy Whitcroft linux-manta (Ubuntu Vivid): status New Won't Fix