A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 3.10.x |
| redhat / enterprise_linux | 7.0 | 7.0.x |