CVE-2018-16597

An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_performance_analytics_services:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*

History

21 Nov 2024, 03:53

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html - Mailing List, Third Party Advisory
References () http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html - () http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html -
References () http://www.securityfocus.com/bid/105394 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/105394 - Third Party Advisory, VDB Entry
References () https://bugzilla.suse.com/show_bug.cgi?id=1106512 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.suse.com/show_bug.cgi?id=1106512 - Issue Tracking, Patch, Third Party Advisory
References () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0ca3d70e8d3cf81e2255a217f7ca402f5ed0862 - Patch, Third Party Advisory () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0ca3d70e8d3cf81e2255a217f7ca402f5ed0862 - Patch, Third Party Advisory
References () https://seclists.org/bugtraq/2019/Jul/33 - () https://seclists.org/bugtraq/2019/Jul/33 -
References () https://security.netapp.com/advisory/ntap-20190204-0001/ - Patch, Third Party Advisory () https://security.netapp.com/advisory/ntap-20190204-0001/ - Patch, Third Party Advisory
References () https://support.f5.com/csp/article/K22691834 - Third Party Advisory () https://support.f5.com/csp/article/K22691834 - Third Party Advisory

Information

Published : 2018-09-21 16:29

Updated : 2024-11-21 03:53


NVD link : CVE-2018-16597

Mitre link : CVE-2018-16597

CVE.ORG link : CVE-2018-16597


JSON object : View

Products Affected

netapp

  • element_software
  • active_iq_performance_analytics_services

linux

  • linux_kernel

opensuse

  • leap
CWE
CWE-863

Incorrect Authorization