The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.
References
Configurations
History
No history.
Information
Published : 2014-10-13 10:55
Updated : 2020-08-14 18:14
NVD link : CVE-2014-7970
Mitre link : CVE-2014-7970
CVE.ORG link : CVE-2014-7970
JSON object : View
Products Affected
canonical
- ubuntu_linux
novell
- suse_linux_enterprise_server
linux
- linux_kernel
CWE
CWE-400
Uncontrolled Resource Consumption