CVE-2016-1576: Canonical Ubuntu Core

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

Affected products

  • Canonical Ubuntu Core: version 15.04 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only; version 16.10 only
  • Canonical Ubuntu Touch: version 15.04 only
  • Linux Linux Kernel: up to and including 4.5.2

Published 2016-05-02. Last modified 2026-06-17.