The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 4.5.2.x |
| canonical / ubuntu_touch | 15.04 | 15.04.x |
| canonical / ubuntu_linux | 16.10 | 16.10.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / ubuntu_core | 15.04 | 15.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 15.10 | 15.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |