CVE-2015-8953: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (dentry reference leak) via filesystem operations on a large file in a lower overlayfs layer.

Affected products

  • Linux Linux Kernel: up to and including 4.2.5

Published 2016-10-16. Last modified 2026-06-17.