An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations, aka CID-ff002b30181d.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-5.3.0-1018-gke", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-gke-5.3-headers-5.3.0-1018", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-gke-5.3-tools-5.3.0-1018", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-headers-5.3.0-1018-gke", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-image-unsigned-5.3.0-1018-gke", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-image-unsigned-5.3.0-1018-gke-dbgsym", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-modules-5.3.0-1018-gke", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-modules-extra-5.3.0-1018-gke", "binary_version": "5.3.0-1018.19~18.04.1" }, { "binary_name": "linux-tools-5.3.0-1018-gke", "binary_version": "5.3.0-1018.19~18.04.1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-5.3.0-1023-raspi2", "binary_version": "5.3.0-1023.25~18.04.1" }, { "binary_name": "linux-headers-5.3.0-1023-raspi2", "binary_version": "5.3.0-1023.25~18.04.1" }, { "binary_name": "linux-image-5.3.0-1023-raspi2", "binary_version": "5.3.0-1023.25~18.04.1" }, { "binary_name": "linux-image-5.3.0-1023-raspi2-dbgsym", "binary_version": "5.3.0-1023.25~18.04.1" }, { "binary_name": "linux-modules-5.3.0-1023-raspi2", "binary_version": "5.3.0-1023.25~18.04.1" }, { "binary_name": "linux-raspi2-5.3-headers-5.3.0-1023", "binary_version": "5.3.0-1023.25~18.04.1" }, { "binary_name": "linux-raspi2-5.3-tools-5.3.0-1023", "binary_version": "5.3.0-1023.25~18.04.1" }, { "binary_name": "linux-tools-5.3.0-1023-raspi2", "binary_version": "5.3.0-1023.25~18.04.1" } ] }