The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxattr call involving a tmpfs filesystem, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7097.
References
Configurations
History
No history.
Information
Published : 2017-02-06 06:59
Updated : 2025-04-20 01:37
NVD link : CVE-2017-5551
Mitre link : CVE-2017-5551
CVE.ORG link : CVE-2017-5551
JSON object : View
Products Affected
linux
- linux_kernel
CWE