Back

MEDIUM

kernel: User can assign an encryption policy to a directory owned by a different user

Published Apr 4, 2017

Description

A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.

Affected products

Remediation

Red Hat statement

This issue does not affect Red Hat Enterprise Linux 5, 6 and 7, MRG and realtime kernels.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 4, 2017
Updated Aug 6, 2024
Reserved Apr 4, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 8, 2016