Rapid7

vulnerability

Ubuntu: (Multiple Advisories) (CVE-2015-1328): Linux kernel vulnerability

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Nov 28, 2016
Added
Nov 8, 2024
Modified
Mar 27, 2026

Description

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

Solutions

ubuntu-upgrade-linux-image-3-13-0-55-genericubuntu-upgrade-linux-image-3-13-0-55-generic-lpaeubuntu-upgrade-linux-image-3-13-0-55-lowlatencyubuntu-upgrade-linux-image-3-13-0-55-powerpc-e500ubuntu-upgrade-linux-image-3-13-0-55-powerpc-e500mcubuntu-upgrade-linux-image-3-13-0-55-powerpc-smpubuntu-upgrade-linux-image-3-13-0-55-powerpc64-embubuntu-upgrade-linux-image-3-13-0-55-powerpc64-smpubuntu-upgrade-linux-image-3-16-0-41-genericubuntu-upgrade-linux-image-3-16-0-41-generic-lpaeubuntu-upgrade-linux-image-3-16-0-41-lowlatencyubuntu-upgrade-linux-image-3-16-0-41-powerpc-e500mcubuntu-upgrade-linux-image-3-16-0-41-powerpc-smpubuntu-upgrade-linux-image-3-16-0-41-powerpc64-embubuntu-upgrade-linux-image-3-16-0-41-powerpc64-smpubuntu-upgrade-linux-image-3-19-0-21-genericubuntu-upgrade-linux-image-3-19-0-21-generic-lpaeubuntu-upgrade-linux-image-3-19-0-21-lowlatencyubuntu-upgrade-linux-image-3-19-0-21-powerpc-e500mcubuntu-upgrade-linux-image-3-19-0-21-powerpc-smpubuntu-upgrade-linux-image-3-19-0-21-powerpc64-embubuntu-upgrade-linux-image-3-19-0-21-powerpc64-smpubuntu-upgrade-linux-image-3-2-0-1466-omap4ubuntu-upgrade-linux-image-3-2-0-86-genericubuntu-upgrade-linux-image-3-2-0-86-generic-paeubuntu-upgrade-linux-image-3-2-0-86-highbankubuntu-upgrade-linux-image-3-2-0-86-omapubuntu-upgrade-linux-image-3-2-0-86-powerpc-smpubuntu-upgrade-linux-image-3-2-0-86-powerpc64-smpubuntu-upgrade-linux-image-3-2-0-86-virtual

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.