CVE-2005-2801 describes a flaw in the xattr.c component of the Linux kernel's ext2 and ext3 file systems (versions 2.6). This vulnerability, a CWE-697, prevents default Access Control Lists (ACLs) from being applied due to improper comparison of name_index fields when sharing xattr blocks. Rated with a CVSS v3.1 score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, potentially leading to high integrity impact by bypassing intended access controls. There is no confidentiality or availability impact. Despite its high severity, there is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.