Upstream information

CVE-2014-5206 at MITRE

Description

The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox protection mechanisms via a "mount -o remount" command within a user namespace.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 7.2
Vector AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entry: 891689

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12
  • kernel-default >= 3.12.28-4.6
  • kernel-default-devel >= 3.12.28-4.6
  • kernel-default-extra >= 3.12.28-4.6
  • kernel-devel >= 3.12.28-4.6
  • kernel-macros >= 3.12.28-4.6
  • kernel-source >= 3.12.28-4.6
  • kernel-syms >= 3.12.28-4.6
  • kernel-xen >= 3.12.28-4.6
  • kernel-xen-devel >= 3.12.28-4.6
Patchnames:
SUSE Linux Enterprise Desktop 12 GA kernel-default
SUSE Linux Enterprise Desktop 12 SP1
  • kernel-default >= 3.12.49-11.1
  • kernel-default-devel >= 3.12.49-11.1
  • kernel-default-extra >= 3.12.49-11.1
  • kernel-devel >= 3.12.49-11.1
  • kernel-macros >= 3.12.49-11.1
  • kernel-source >= 3.12.49-11.1
  • kernel-syms >= 3.12.49-11.1
  • kernel-xen >= 3.12.49-11.1
  • kernel-xen-devel >= 3.12.49-11.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA kernel-default
SUSE Linux Enterprise Server 12
  • kernel-default >= 3.12.28-4.6
  • kernel-default-base >= 3.12.28-4.6
  • kernel-default-devel >= 3.12.28-4.6
  • kernel-default-man >= 3.12.28-4.6
  • kernel-devel >= 3.12.28-4.6
  • kernel-macros >= 3.12.28-4.6
  • kernel-source >= 3.12.28-4.6
  • kernel-syms >= 3.12.28-4.6
  • kernel-xen >= 3.12.28-4.6
  • kernel-xen-base >= 3.12.28-4.6
  • kernel-xen-devel >= 3.12.28-4.6
Patchnames:
SUSE Linux Enterprise Server 12 GA kernel-default
SUSE Linux Enterprise Server 12 SP1
  • kernel-default >= 3.12.49-11.1
  • kernel-default-base >= 3.12.49-11.1
  • kernel-default-devel >= 3.12.49-11.1
  • kernel-default-man >= 3.12.49-11.1
  • kernel-devel >= 3.12.49-11.1
  • kernel-macros >= 3.12.49-11.1
  • kernel-source >= 3.12.49-11.1
  • kernel-syms >= 3.12.49-11.1
  • kernel-xen >= 3.12.49-11.1
  • kernel-xen-base >= 3.12.49-11.1
  • kernel-xen-devel >= 3.12.49-11.1
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA kernel-default
SUSE Linux Enterprise Software Development Kit 12
  • kernel-docs >= 3.12.28-4.6
  • kernel-obs-build >= 3.12.28-4.3
  • kernel-zfcpdump >= 3.12.28-4.2
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 GA kernel-docs
SUSE Linux Enterprise Software Development Kit 12 SP1
  • kernel-docs >= 3.12.49-11.1
  • kernel-obs-build >= 3.12.49-11.2
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP1 GA kernel-docs
SUSE Linux Enterprise Workstation Extension 12
  • kernel-default-extra >= 3.12.28-4.6
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 GA kernel-default-extra
SUSE Linux Enterprise Workstation Extension 12 SP1
  • kernel-default-extra >= 3.12.49-11.1
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 SP1 GA kernel-default-extra
openSUSE 13.1
  • cloop >= 2.639-11.16.1
  • cloop-debuginfo >= 2.639-11.16.1
  • cloop-debugsource >= 2.639-11.16.1
  • cloop-kmp-default >= 2.639_k3.11.10_25-11.16.1
  • cloop-kmp-default-debuginfo >= 2.639_k3.11.10_25-11.16.1
  • cloop-kmp-desktop >= 2.639_k3.11.10_25-11.16.1
  • cloop-kmp-desktop-debuginfo >= 2.639_k3.11.10_25-11.16.1
  • cloop-kmp-pae >= 2.639_k3.11.10_25-11.16.1
  • cloop-kmp-pae-debuginfo >= 2.639_k3.11.10_25-11.16.1
  • cloop-kmp-xen >= 2.639_k3.11.10_25-11.16.1
  • cloop-kmp-xen-debuginfo >= 2.639_k3.11.10_25-11.16.1
  • crash >= 7.0.2-2.16.1
  • crash-debuginfo >= 7.0.2-2.16.1
  • crash-debugsource >= 7.0.2-2.16.1
  • crash-devel >= 7.0.2-2.16.1
  • crash-doc >= 7.0.2-2.16.1
  • crash-eppic >= 7.0.2-2.16.1
  • crash-eppic-debuginfo >= 7.0.2-2.16.1
  • crash-gcore >= 7.0.2-2.16.1
  • crash-gcore-debuginfo >= 7.0.2-2.16.1
  • crash-kmp-default >= 7.0.2_k3.11.10_25-2.16.1
  • crash-kmp-default-debuginfo >= 7.0.2_k3.11.10_25-2.16.1
  • crash-kmp-desktop >= 7.0.2_k3.11.10_25-2.16.1
  • crash-kmp-desktop-debuginfo >= 7.0.2_k3.11.10_25-2.16.1
  • crash-kmp-pae >= 7.0.2_k3.11.10_25-2.16.1
  • crash-kmp-pae-debuginfo >= 7.0.2_k3.11.10_25-2.16.1
  • crash-kmp-xen >= 7.0.2_k3.11.10_25-2.16.1
  • crash-kmp-xen-debuginfo >= 7.0.2_k3.11.10_25-2.16.1
  • hdjmod >= 1.28-16.16.1
  • hdjmod-debugsource >= 1.28-16.16.1
  • hdjmod-kmp-default >= 1.28_k3.11.10_25-16.16.1
  • hdjmod-kmp-default-debuginfo >= 1.28_k3.11.10_25-16.16.1
  • hdjmod-kmp-desktop >= 1.28_k3.11.10_25-16.16.1
  • hdjmod-kmp-desktop-debuginfo >= 1.28_k3.11.10_25-16.16.1
  • hdjmod-kmp-pae >= 1.28_k3.11.10_25-16.16.1
  • hdjmod-kmp-pae-debuginfo >= 1.28_k3.11.10_25-16.16.1
  • hdjmod-kmp-xen >= 1.28_k3.11.10_25-16.16.1
  • hdjmod-kmp-xen-debuginfo >= 1.28_k3.11.10_25-16.16.1
  • ipset >= 6.21.1-2.20.1
  • ipset-debuginfo >= 6.21.1-2.20.1
  • ipset-debugsource >= 6.21.1-2.20.1
  • ipset-devel >= 6.21.1-2.20.1
  • ipset-kmp-default >= 6.21.1_k3.11.10_25-2.20.1
  • ipset-kmp-default-debuginfo >= 6.21.1_k3.11.10_25-2.20.1
  • ipset-kmp-desktop >= 6.21.1_k3.11.10_25-2.20.1
  • ipset-kmp-desktop-debuginfo >= 6.21.1_k3.11.10_25-2.20.1
  • ipset-kmp-pae >= 6.21.1_k3.11.10_25-2.20.1
  • ipset-kmp-pae-debuginfo >= 6.21.1_k3.11.10_25-2.20.1
  • ipset-kmp-xen >= 6.21.1_k3.11.10_25-2.20.1
  • ipset-kmp-xen-debuginfo >= 6.21.1_k3.11.10_25-2.20.1
  • iscsitarget >= 1.4.20.3-13.16.1
  • iscsitarget-debuginfo >= 1.4.20.3-13.16.1
  • iscsitarget-debugsource >= 1.4.20.3-13.16.1
  • iscsitarget-kmp-default >= 1.4.20.3_k3.11.10_25-13.16.1
  • iscsitarget-kmp-default-debuginfo >= 1.4.20.3_k3.11.10_25-13.16.1
  • iscsitarget-kmp-desktop >= 1.4.20.3_k3.11.10_25-13.16.1
  • iscsitarget-kmp-desktop-debuginfo >= 1.4.20.3_k3.11.10_25-13.16.1
  • iscsitarget-kmp-pae >= 1.4.20.3_k3.11.10_25-13.16.1
  • iscsitarget-kmp-pae-debuginfo >= 1.4.20.3_k3.11.10_25-13.16.1
  • iscsitarget-kmp-xen >= 1.4.20.3_k3.11.10_25-13.16.1
  • iscsitarget-kmp-xen-debuginfo >= 1.4.20.3_k3.11.10_25-13.16.1
  • kernel-debug >= 3.11.10-25.1
  • kernel-debug-base >= 3.11.10-25.1
  • kernel-debug-base-debuginfo >= 3.11.10-25.1
  • kernel-debug-debuginfo >= 3.11.10-25.1
  • kernel-debug-debugsource >= 3.11.10-25.1
  • kernel-debug-devel >= 3.11.10-25.1
  • kernel-debug-devel-debuginfo >= 3.11.10-25.1
  • kernel-default >= 3.11.10-25.1
  • kernel-default-base >= 3.11.10-25.1
  • kernel-default-base-debuginfo >= 3.11.10-25.1
  • kernel-default-debuginfo >= 3.11.10-25.1
  • kernel-default-debugsource >= 3.11.10-25.1
  • kernel-default-devel >= 3.11.10-25.1
  • kernel-default-devel-debuginfo >= 3.11.10-25.1
  • kernel-desktop >= 3.11.10-25.1
  • kernel-desktop-base >= 3.11.10-25.1
  • kernel-desktop-base-debuginfo >= 3.11.10-25.1
  • kernel-desktop-debuginfo >= 3.11.10-25.1
  • kernel-desktop-debugsource >= 3.11.10-25.1
  • kernel-desktop-devel >= 3.11.10-25.1
  • kernel-desktop-devel-debuginfo >= 3.11.10-25.1
  • kernel-devel >= 3.11.10-25.1
  • kernel-docs >= 3.11.10-25.2
  • kernel-ec2 >= 3.11.10-25.1
  • kernel-ec2-base >= 3.11.10-25.1
  • kernel-ec2-base-debuginfo >= 3.11.10-25.1
  • kernel-ec2-debuginfo >= 3.11.10-25.1
  • kernel-ec2-debugsource >= 3.11.10-25.1
  • kernel-ec2-devel >= 3.11.10-25.1
  • kernel-ec2-devel-debuginfo >= 3.11.10-25.1
  • kernel-pae >= 3.11.10-25.1
  • kernel-pae-base >= 3.11.10-25.1
  • kernel-pae-base-debuginfo >= 3.11.10-25.1
  • kernel-pae-debuginfo >= 3.11.10-25.1
  • kernel-pae-debugsource >= 3.11.10-25.1
  • kernel-pae-devel >= 3.11.10-25.1
  • kernel-pae-devel-debuginfo >= 3.11.10-25.1
  • kernel-source >= 3.11.10-25.1
  • kernel-source-vanilla >= 3.11.10-25.1
  • kernel-syms >= 3.11.10-25.1
  • kernel-trace >= 3.11.10-25.1
  • kernel-trace-base >= 3.11.10-25.1
  • kernel-trace-base-debuginfo >= 3.11.10-25.1
  • kernel-trace-debuginfo >= 3.11.10-25.1
  • kernel-trace-debugsource >= 3.11.10-25.1
  • kernel-trace-devel >= 3.11.10-25.1
  • kernel-trace-devel-debuginfo >= 3.11.10-25.1
  • kernel-vanilla >= 3.11.10-25.1
  • kernel-vanilla-debuginfo >= 3.11.10-25.1
  • kernel-vanilla-debugsource >= 3.11.10-25.1
  • kernel-vanilla-devel >= 3.11.10-25.1
  • kernel-vanilla-devel-debuginfo >= 3.11.10-25.1
  • kernel-xen >= 3.11.10-25.1
  • kernel-xen-base >= 3.11.10-25.1
  • kernel-xen-base-debuginfo >= 3.11.10-25.1
  • kernel-xen-debuginfo >= 3.11.10-25.1
  • kernel-xen-debugsource >= 3.11.10-25.1
  • kernel-xen-devel >= 3.11.10-25.1
  • kernel-xen-devel-debuginfo >= 3.11.10-25.1
  • libipset3 >= 6.21.1-2.20.1
  • libipset3-debuginfo >= 6.21.1-2.20.1
  • ndiswrapper >= 1.58-16.1
  • ndiswrapper-debuginfo >= 1.58-16.1
  • ndiswrapper-debugsource >= 1.58-16.1
  • ndiswrapper-kmp-default >= 1.58_k3.11.10_25-16.1
  • ndiswrapper-kmp-default-debuginfo >= 1.58_k3.11.10_25-16.1
  • ndiswrapper-kmp-desktop >= 1.58_k3.11.10_25-16.1
  • ndiswrapper-kmp-desktop-debuginfo >= 1.58_k3.11.10_25-16.1
  • ndiswrapper-kmp-pae >= 1.58_k3.11.10_25-16.1
  • ndiswrapper-kmp-pae-debuginfo >= 1.58_k3.11.10_25-16.1
  • pcfclock >= 0.44-258.16.1
  • pcfclock-debuginfo >= 0.44-258.16.1
  • pcfclock-debugsource >= 0.44-258.16.1
  • pcfclock-kmp-default >= 0.44_k3.11.10_25-258.16.1
  • pcfclock-kmp-default-debuginfo >= 0.44_k3.11.10_25-258.16.1
  • pcfclock-kmp-desktop >= 0.44_k3.11.10_25-258.16.1
  • pcfclock-kmp-desktop-debuginfo >= 0.44_k3.11.10_25-258.16.1
  • pcfclock-kmp-pae >= 0.44_k3.11.10_25-258.16.1
  • pcfclock-kmp-pae-debuginfo >= 0.44_k3.11.10_25-258.16.1
  • python-virtualbox >= 4.2.18-2.21.1
  • python-virtualbox-debuginfo >= 4.2.18-2.21.1
  • vhba-kmp >= 20130607-2.17.1
  • vhba-kmp-debugsource >= 20130607-2.17.1
  • vhba-kmp-default >= 20130607_k3.11.10_25-2.17.1
  • vhba-kmp-default-debuginfo >= 20130607_k3.11.10_25-2.17.1
  • vhba-kmp-desktop >= 20130607_k3.11.10_25-2.17.1
  • vhba-kmp-desktop-debuginfo >= 20130607_k3.11.10_25-2.17.1
  • vhba-kmp-pae >= 20130607_k3.11.10_25-2.17.1
  • vhba-kmp-pae-debuginfo >= 20130607_k3.11.10_25-2.17.1
  • vhba-kmp-xen >= 20130607_k3.11.10_25-2.17.1
  • vhba-kmp-xen-debuginfo >= 20130607_k3.11.10_25-2.17.1
  • virtualbox >= 4.2.18-2.21.1
  • virtualbox-debuginfo >= 4.2.18-2.21.1
  • virtualbox-debugsource >= 4.2.18-2.21.1
  • virtualbox-devel >= 4.2.18-2.21.1
  • virtualbox-guest-kmp-default >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-guest-kmp-default-debuginfo >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-guest-kmp-desktop >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-guest-kmp-desktop-debuginfo >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-guest-kmp-pae >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-guest-kmp-pae-debuginfo >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-guest-tools >= 4.2.18-2.21.1
  • virtualbox-guest-tools-debuginfo >= 4.2.18-2.21.1
  • virtualbox-guest-x11 >= 4.2.18-2.21.1
  • virtualbox-guest-x11-debuginfo >= 4.2.18-2.21.1
  • virtualbox-host-kmp-default >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-host-kmp-default-debuginfo >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-host-kmp-desktop >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-host-kmp-desktop-debuginfo >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-host-kmp-pae >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-host-kmp-pae-debuginfo >= 4.2.18_k3.11.10_25-2.21.1
  • virtualbox-qt >= 4.2.18-2.21.1
  • virtualbox-qt-debuginfo >= 4.2.18-2.21.1
  • virtualbox-websrv >= 4.2.18-2.21.1
  • virtualbox-websrv-debuginfo >= 4.2.18-2.21.1
  • xen >= 4.3.2_02-30.1
  • xen-debugsource >= 4.3.2_02-30.1
  • xen-devel >= 4.3.2_02-30.1
  • xen-doc-html >= 4.3.2_02-30.1
  • xen-kmp-default >= 4.3.2_02_k3.11.10_25-30.1
  • xen-kmp-default-debuginfo >= 4.3.2_02_k3.11.10_25-30.1
  • xen-kmp-desktop >= 4.3.2_02_k3.11.10_25-30.1
  • xen-kmp-desktop-debuginfo >= 4.3.2_02_k3.11.10_25-30.1
  • xen-kmp-pae >= 4.3.2_02_k3.11.10_25-30.1
  • xen-kmp-pae-debuginfo >= 4.3.2_02_k3.11.10_25-30.1
  • xen-libs >= 4.3.2_02-30.1
  • xen-libs-32bit >= 4.3.2_02-30.1
  • xen-libs-debuginfo >= 4.3.2_02-30.1
  • xen-libs-debuginfo-32bit >= 4.3.2_02-30.1
  • xen-tools >= 4.3.2_02-30.1
  • xen-tools-debuginfo >= 4.3.2_02-30.1
  • xen-tools-domU >= 4.3.2_02-30.1
  • xen-tools-domU-debuginfo >= 4.3.2_02-30.1
  • xen-xend-tools >= 4.3.2_02-30.1
  • xen-xend-tools-debuginfo >= 4.3.2_02-30.1
  • xtables-addons >= 2.3-2.16.1
  • xtables-addons-debuginfo >= 2.3-2.16.1
  • xtables-addons-debugsource >= 2.3-2.16.1
  • xtables-addons-kmp-default >= 2.3_k3.11.10_25-2.16.1
  • xtables-addons-kmp-default-debuginfo >= 2.3_k3.11.10_25-2.16.1
  • xtables-addons-kmp-desktop >= 2.3_k3.11.10_25-2.16.1
  • xtables-addons-kmp-desktop-debuginfo >= 2.3_k3.11.10_25-2.16.1
  • xtables-addons-kmp-pae >= 2.3_k3.11.10_25-2.16.1
  • xtables-addons-kmp-pae-debuginfo >= 2.3_k3.11.10_25-2.16.1
  • xtables-addons-kmp-xen >= 2.3_k3.11.10_25-2.16.1
  • xtables-addons-kmp-xen-debuginfo >= 2.3_k3.11.10_25-2.16.1
Patchnames:
openSUSE-2014-793