CVE-2014-5206: Canonical Ubuntu Linux
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox protection mechanisms via a "mount -o remount" command within a user namespace.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Linux Linux Kernel: from 3.8, before 3.10.55 (fixed in 3.10.55); from 3.11, before 3.12.27 (fixed in 3.12.27); from 3.13, before 3.14.19 (fixed in 3.14.19); from 3.15, before 3.16.3 (fixed in 3.16.3)
Published 2014-08-18. Last modified 2026-06-17.