CVE Vulnerabilities

CVE-2013-1957

Published: Apr 24, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.7 MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The clone_mnt function in fs/namespace.c in the Linux kernel before 3.8.6 does not properly restrict changes to the MNT_READONLY flag, which allows local users to bypass an intended read-only property of a filesystem by leveraging a separate mount namespace.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*3.8.5 (including)
Linux_kernelLinux3.8.0 (including)3.8.0 (including)
Linux_kernelLinux3.8.1 (including)3.8.1 (including)
Linux_kernelLinux3.8.2 (including)3.8.2 (including)
Linux_kernelLinux3.8.3 (including)3.8.3 (including)
Linux_kernelLinux3.8.4 (including)3.8.4 (including)
LinuxUbuntuupstream*
Linux-armadaxpUbuntuupstream*
Linux-ec2Ubuntuupstream*
Linux-fsl-imx51Ubuntulucid*
Linux-fsl-imx51Ubuntuupstream*
Linux-linaro-omapUbuntudevel*
Linux-linaro-omapUbuntuoneiric*
Linux-linaro-omapUbuntuprecise*
Linux-linaro-omapUbuntuquantal*
Linux-linaro-omapUbuntuupstream*
Linux-linaro-sharedUbuntudevel*
Linux-linaro-sharedUbuntuoneiric*
Linux-linaro-sharedUbuntuprecise*
Linux-linaro-sharedUbuntuquantal*
Linux-linaro-sharedUbuntuupstream*
Linux-linaro-vexpressUbuntudevel*
Linux-linaro-vexpressUbuntuoneiric*
Linux-linaro-vexpressUbuntuprecise*
Linux-linaro-vexpressUbuntuquantal*
Linux-linaro-vexpressUbuntuupstream*
Linux-lts-backport-maverickUbuntulucid*
Linux-lts-backport-maverickUbuntuupstream*
Linux-lts-backport-oneiricUbuntuupstream*
Linux-lts-quantalUbuntuupstream*
Linux-mvl-doveUbuntulucid*
Linux-mvl-doveUbuntuupstream*
Linux-qcm-msmUbuntudevel*
Linux-qcm-msmUbuntulucid*
Linux-qcm-msmUbuntuoneiric*
Linux-qcm-msmUbuntuprecise*
Linux-qcm-msmUbuntuquantal*
Linux-qcm-msmUbuntuupstream*
Linux-ti-omap4Ubuntuupstream*

References