MEDIUM
fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem
Published Aug 31, 2016
5.5
MEDIUMCVSS 3.0
EPSS 0.37%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.