CVE-2014-9717

Source
https://nvd.nist.gov/vuln/detail/CVE-2014-9717
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-9717.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-9717
Downstream
Related
Published
2016-05-02T10:59:06Z
Modified
2025-08-09T20:01:27Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N CVSS Calculator
Summary
[none]
Details

fs/namespace.c in the Linux kernel before 4.0.2 processes MNTDETACH umount2 system calls without verifying that the MNTLOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.

References

Affected packages