The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.0.0 | 4.20.15.x |
| linux / linux_kernel | 3.0.0 | 3.19.8.x |