CVE-2016-1575 (linux_kernel, ubuntu_core, ubuntu_linux, ubuntu_touch)

CVE-2016-1575 (linux_kernel, ubuntu_core, ubuntu_linux, ubuntu_touch)

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

Source: CVE-2016-1575 (linux_kernel, ubuntu_core, ubuntu_linux, ubuntu_touch)

CVE-2015-8839

CVE-2015-8839

Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user’s file after unsynchronized hole punching and page-fault handling.

Source: CVE-2015-8839