CVE-2015-8660: Linux Kernel
Medium severity, CVSS 6.7. EPSS: 22.2% chance of exploitation in the next 30 days.
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
Affected products
- Linux Linux Kernel: from 3.18, before 3.18.31 (fixed in 3.18.31); from 3.19, before 4.1.22 (fixed in 4.1.22); from 4.2, before 4.4 (fixed in 4.4)
Published 2015-12-28. Last modified 2026-06-17.