CVE-2015-1328 describes a local privilege escalation vulnerability in the overlayfs implementation of the Linux kernel, specifically affecting Ubuntu versions up to 15.04. The flaw allows local users to gain root access due to improper permission checks during file creation in the upper filesystem directory when overlayfs is permitted in an arbitrary mount namespace. This vulnerability carries a CVSS v3 score of 7.8 (High), indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including Metasploit modules and ExploitDB entries, and the vulnerability has garnered significant community discussion and media coverage, although it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:* | ||
<= 3.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.