Executive brief
A vulnerability in the Linux kernel's file system handling could allow a local user to improperly modify how file ownership is mapped on certain disk mounts. This flaw bypasses intended security restrictions designed to prevent data corruption or unauthorized access during mount operations. If exploited, it could lead to system instability or allow an attacker to gain unauthorized access to sensitive information.
Technical details
A vulnerability exists in the Linux kernel's fs/namespace.c where the open_tree_attr(2) system call failed to enforce the OPEN_TREE_CLONE requirement for id-mapping changes. While can_idmap_mount() protected attached mountpoints, detached but visible mounts remained vulnerable to unauthorized id-mapping modifications. This flaw stems from a logic error in the handling of MOUNT_KATTR_IDMAP_REPLACE flags. An attacker with local access could exploit this to trigger use-after-free (UAF) conditions or locking issues, potentially leading to privilege escalation or a kernel crash. The issue has been patched by ensuring id-mapping changes are only permitted when a mount is being cloned.
Affected products
- Linux Linux Kernel 6.15 to 6.16.4
Timeline
- 2025-08-08: other: Patch authored
- 2025-09-05: disclosed: CVE published
- 2025-08-28: patched: Patch committed to stable tree