CVE-2015-8660: Linux Kernel

Medium severity, CVSS 6.7. EPSS: 22.2% chance of exploitation in the next 30 days.

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

Affected products

  • Linux Linux Kernel: from 3.18, before 3.18.31 (fixed in 3.18.31); from 3.19, before 4.1.22 (fixed in 4.1.22); from 4.2, before 4.4 (fixed in 4.4)

Published 2015-12-28. Last modified 2026-06-17.