CVE-2014-8989
Bug #1395189 reported by
John Johansen
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Won't Fix
|
Medium
|
Unassigned | ||
Trusty |
Fix Released
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-armadaxp (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Won't Fix
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-ec2 (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-flo (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Medium
|
Unassigned | ||
Wily |
New
|
Medium
|
Unassigned | ||
Xenial |
New
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-fsl-imx51 (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-goldfish (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Medium
|
Unassigned | ||
Wily |
New
|
Medium
|
Unassigned | ||
Xenial |
New
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-lts-backport-maverick (Ubuntu) |
New
|
Undecided
|
Unassigned | ||
Lucid |
Won't Fix
|
Undecided
|
Unassigned | ||
Precise |
Won't Fix
|
Undecided
|
Unassigned | ||
Trusty |
New
|
Undecided
|
Unassigned | ||
Utopic |
Won't Fix
|
Undecided
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
New
|
Undecided
|
Unassigned | ||
Xenial |
New
|
Undecided
|
Unassigned | ||
Yakkety |
New
|
Undecided
|
Unassigned | ||
linux-lts-backport-natty (Ubuntu) |
New
|
Undecided
|
Unassigned | ||
Lucid |
Won't Fix
|
Undecided
|
Unassigned | ||
Precise |
Won't Fix
|
Undecided
|
Unassigned | ||
Trusty |
New
|
Undecided
|
Unassigned | ||
Utopic |
Won't Fix
|
Undecided
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
New
|
Undecided
|
Unassigned | ||
Xenial |
New
|
Undecided
|
Unassigned | ||
Yakkety |
New
|
Undecided
|
Unassigned | ||
linux-lts-quantal (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-raring (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-saucy (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-trusty (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Fix Released
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-utopic (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Fix Released
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-vivid (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Fix Committed
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-wily (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-xenial (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Fix Committed
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-mako (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Medium
|
Unassigned | ||
Wily |
New
|
Medium
|
Unassigned | ||
Xenial |
New
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-manta (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Medium
|
Unassigned | ||
Wily |
New
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-mvl-dove (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-raspi2 (Ubuntu) |
Fix Committed
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Fix Committed
|
Medium
|
Unassigned | ||
Yakkety |
Fix Committed
|
Medium
|
Unassigned | ||
linux-snapdragon (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-ti-omap4 (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Won't Fix
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Invalid
|
Medium
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned |
Bug Description
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/
Break-Fix: - 273d2c67c3e179a
Break-Fix: - be7c6dba2332cef
Break-Fix: - 80dd00a23784b38
Break-Fix: - f95d7918bd1e724
CVE References
description: | updated |
Changed in linux-lts-trusty (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-lts-trusty (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-trusty (Ubuntu Lucid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-trusty (Ubuntu Vivid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-trusty (Ubuntu Utopic): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Lucid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Vivid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Utopic): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-raring (Ubuntu Precise): | |
status: | New → Invalid |
description: | updated |
Changed in linux (Ubuntu Vivid): | |
status: | New → Fix Committed |
Changed in linux-flo (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Lucid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Vivid): | |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Utopic): | |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Lucid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Vivid): | |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Utopic): | |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Lucid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Vivid): | |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Utopic): | |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Lucid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Vivid): | |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Utopic): | |
importance: | Undecided → Medium |
Changed in linux-lts-trusty (Ubuntu Precise): | |
status: | New → Fix Committed |
Changed in linux-lts-utopic (Ubuntu Trusty): | |
status: | New → Fix Committed |
Changed in linux (Ubuntu Trusty): | |
status: | New → Fix Committed |
Changed in linux (Ubuntu Utopic): | |
status: | New → Fix Committed |
Changed in linux-lts-trusty (Ubuntu Precise): | |
status: | Fix Committed → Fix Released |
Changed in linux-lts-utopic (Ubuntu Trusty): | |
status: | Fix Committed → Fix Released |
Changed in linux (Ubuntu Trusty): | |
status: | Fix Committed → Fix Released |
Changed in linux (Ubuntu Utopic): | |
status: | Fix Committed → Fix Released |
Changed in linux-lts-saucy (Ubuntu Precise): | |
status: | New → Fix Committed |
Changed in linux (Ubuntu Vivid): | |
status: | Fix Committed → Invalid |
Changed in linux-lts-saucy (Ubuntu Precise): | |
status: | Fix Committed → Invalid |
Changed in linux-lts-quantal (Ubuntu Precise): | |
status: | New → Invalid |
no longer affects: | linux-lts-trusty (Ubuntu Lucid) |
no longer affects: | linux-armadaxp (Ubuntu Lucid) |
no longer affects: | linux-ec2 (Ubuntu Lucid) |
no longer affects: | linux-goldfish (Ubuntu Lucid) |
no longer affects: | linux-lts-saucy (Ubuntu Lucid) |
no longer affects: | linux-lts-quantal (Ubuntu Lucid) |
no longer affects: | linux-mvl-dove (Ubuntu Lucid) |
no longer affects: | linux-ti-omap4 (Ubuntu Lucid) |
no longer affects: | linux (Ubuntu Lucid) |
no longer affects: | linux-mako (Ubuntu Lucid) |
no longer affects: | linux-fsl-imx51 (Ubuntu Lucid) |
no longer affects: | linux-lts-utopic (Ubuntu Lucid) |
no longer affects: | linux-flo (Ubuntu Lucid) |
no longer affects: | linux-lts-raring (Ubuntu Lucid) |
no longer affects: | linux-manta (Ubuntu Lucid) |
Changed in linux-lts-vivid (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Vivid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Wily): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Utopic): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Trusty): | |
status: | New → Fix Committed |
importance: | Undecided → Medium |
no longer affects: | linux-lts-trusty (Ubuntu Utopic) |
no longer affects: | linux-armadaxp (Ubuntu Utopic) |
no longer affects: | linux-ec2 (Ubuntu Utopic) |
no longer affects: | linux-goldfish (Ubuntu Utopic) |
no longer affects: | linux-lts-saucy (Ubuntu Utopic) |
no longer affects: | linux-lts-quantal (Ubuntu Utopic) |
no longer affects: | linux-mvl-dove (Ubuntu Utopic) |
no longer affects: | linux-ti-omap4 (Ubuntu Utopic) |
no longer affects: | linux-lts-vivid (Ubuntu Utopic) |
no longer affects: | linux (Ubuntu Utopic) |
no longer affects: | linux-mako (Ubuntu Utopic) |
no longer affects: | linux-fsl-imx51 (Ubuntu Utopic) |
no longer affects: | linux-lts-utopic (Ubuntu Utopic) |
no longer affects: | linux-flo (Ubuntu Utopic) |
no longer affects: | linux-lts-raring (Ubuntu Utopic) |
no longer affects: | linux-manta (Ubuntu Utopic) |
Changed in linux-lts-wily (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-wily (Ubuntu Wily): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-wily (Ubuntu Xenial): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-wily (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-wily (Ubuntu Vivid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Wily): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Xenial): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Vivid): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Xenial): | |
status: | Invalid → Fix Committed |
Changed in linux-lts-xenial (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Wily): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Xenial): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Trusty): | |
status: | New → Fix Committed |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Xenial): | |
status: | New → Invalid |
Changed in linux-lts-backport-maverick (Ubuntu Utopic): | |
status: | New → Won't Fix |
Changed in linux-lts-backport-natty (Ubuntu Utopic): | |
status: | New → Won't Fix |
Changed in linux-snapdragon (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Wily): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Xenial): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Yakkety): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-backport-maverick (Ubuntu Precise): | |
status: | New → Won't Fix |
Changed in linux-lts-backport-natty (Ubuntu Precise): | |
status: | New → Won't Fix |
To post a comment you must log in.
CVE-2014-8989