The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.0 | 3.19.8.x |
| redhat / enterprise_linux | 7.0 | 7.0.x |
| redhat / enterprise_linux | 6.0 | 6.0.x |
| redhat / enterprise_linux | 5.0 | 5.0.x |
| redhat / enterprise_mrg | 2.0 | 2.0.x |