Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 325603 (CVE-2010-2071) - Kernel: btrfs_xattr_set_acl() file permission bypass (CVE-2010-2071)
Summary: Kernel: btrfs_xattr_set_acl() file permission bypass (CVE-2010-2071)
Status: RESOLVED FIXED
Alias: CVE-2010-2071
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://git.kernel.org/?p=linux/kernel...
Whiteboard: [ linux < 2.6.34 ]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-06-25 21:14 UTC by Stefan Behte (RETIRED)
Modified: 2013-09-15 19:37 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 21:14:29 UTC
CVE-2010-2071 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2071):
  The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the
  Linux kernel 2.6.34 and earlier does not check file ownership before
  setting an ACL, which allows local users to bypass file permissions
  by setting arbitrary ACLs, as demonstrated using setfacl.