Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-2925

18
FAUCET Score

CVE-2015-2925 describes a vulnerability in the Linux kernel, specifically affecting versions prior to 4.2.4, where the prepend_path function mishandles rename operations within bind mounts. This flaw allows local users to bypass container protection mechanisms through a "double-chroot attack" by renaming directories. With a CVSS score of 6.9, this vulnerability is considered high severity, requiring local access and medium attack complexity, but potentially leading to complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.72CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.3, < 3.4.110CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.5, < 3.10.91CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.12.49CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.14.55CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.9MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.25%
Probability of exploitation in next 30 days
EPSS Percentile
66.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0125 is in the 92nd percentile among its peer group of 1,595 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-573.12.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-327.rt56.204.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-327.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.1 Extended Update SupportFixed in: kernel-0:3.10.0-229.24.2.ael7b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-327.rt56.170.el6rt
View patch

Vendor Advisories (1)

redhatCVE-2015-2925Important

Kernel: vfs: Do not allow escaping from bind mounts

Apr 3, 2015

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Third Party Advisory
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-12/msg00005.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-12/msg00018.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00009.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00017.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00018.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00019.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00020.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00021.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00022.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00034.html
Mailing ListThird Party Advisory
permalink.gmane.org / gmane.linux.kernel.containers/29173
Broken Link
permalink.gmane.org / gmane.linux.kernel.containers/29177
Broken Link
pkgs.fedoraproject.org / cgit/kernel.git/commit
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-2636.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-0068.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / torvalds/linux/commit/397d425dc26da728396e66d392d5dcb8dac30c37
Third Party Advisory
github.com / torvalds/linux/commit/cde93be45a8a90d8c264c776fab63487b5038a65
Third Party Advisory
debian.org / security/2015/dsa-3364
Third Party Advisory
debian.org / security/2015/dsa-3372
Third Party Advisory
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.2.4
Vendor Advisory
openwall.com / lists/oss-security/2015/04/04/4
Mailing ListThird Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinjan2016-2867209.html
Third Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinoct2015-2719645.html
Third Party Advisory
securityfocus.com / bid/73926
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2792-1
Third Party Advisory
ubuntu.com / usn/USN-2794-1
Third Party Advisory
ubuntu.com / usn/USN-2795-1
Third Party Advisory
ubuntu.com / usn/USN-2798-1
Third Party Advisory
ubuntu.com / usn/USN-2799-1
Third Party Advisory