CVE-2011-1833

Race condition in the ecryptfs_mount function in fs/ecryptfs/main.c in the eCryptfs subsystem in the Linux kernel before 3.1 allows local users to bypass intended file permissions via a mount.ecryptfs_private mount with a mismatched uid.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 3.0.44
linuxlinux_kernel
3.0:rc1
linuxlinux_kernel
3.0:rc2
linuxlinux_kernel
3.0:rc3
linuxlinux_kernel
3.0:rc4
linuxlinux_kernel
3.0:rc5
linuxlinux_kernel
3.0:rc6
linuxlinux_kernel
3.0:rc7
linuxlinux_kernel
3.0.1
linuxlinux_kernel
3.0.2
linuxlinux_kernel
3.0.3
linuxlinux_kernel
3.0.4
linuxlinux_kernel
3.0.5
linuxlinux_kernel
3.0.6
linuxlinux_kernel
3.0.7
linuxlinux_kernel
3.0.8
linuxlinux_kernel
3.0.9
linuxlinux_kernel
3.0.10
linuxlinux_kernel
3.0.11
linuxlinux_kernel
3.0.12
linuxlinux_kernel
3.0.13
linuxlinux_kernel
3.0.14
linuxlinux_kernel
3.0.15
linuxlinux_kernel
3.0.16
linuxlinux_kernel
3.0.17
linuxlinux_kernel
3.0.18
linuxlinux_kernel
3.0.19
linuxlinux_kernel
3.0.20
linuxlinux_kernel
3.0.21
linuxlinux_kernel
3.0.22
linuxlinux_kernel
3.0.23
linuxlinux_kernel
3.0.24
linuxlinux_kernel
3.0.25
linuxlinux_kernel
3.0.26
linuxlinux_kernel
3.0.27
linuxlinux_kernel
3.0.28
linuxlinux_kernel
3.0.29
linuxlinux_kernel
3.0.30
linuxlinux_kernel
3.0.31
linuxlinux_kernel
3.0.32
linuxlinux_kernel
3.0.33
linuxlinux_kernel
3.0.34
linuxlinux_kernel
3.0.35
linuxlinux_kernel
3.0.36
linuxlinux_kernel
3.0.37
linuxlinux_kernel
3.0.38
linuxlinux_kernel
3.0.39
linuxlinux_kernel
3.0.40
linuxlinux_kernel
3.0.41
linuxlinux_kernel
3.0.42
linuxlinux_kernel
3.0.43
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ecryptfs-utils
bookworm
111-6
fixed
bullseye
111-5
fixed
sid
111-7
fixed
squeeze
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ecryptfs-utils
hardy
not-affected
lucid
Fixed 83-0ubuntu3.2.10.04.1
released
maverick
Fixed 83-0ubuntu3.2.10.10.1
released
natty
Fixed 87-0ubuntu1.1
released
oneiric
Fixed 89-0ubuntu2
released
linux
hardy
not-affected
lucid
Fixed 2.6.32-35.78
released
maverick
Fixed 2.6.35-30.60
released
natty
Fixed 2.6.38-11.49
released
oneiric
not-affected
linux-ec2
hardy
dne
lucid
Fixed 2.6.32-319.39
released
maverick
ignored
natty
dne
oneiric
dne
linux-fsl-imx51
hardy
dne
lucid
Fixed 2.6.31-610.27
released
maverick
dne
natty
dne
oneiric
dne
linux-lts-backport-maverick
hardy
dne
lucid
Fixed 2.6.35-30.60~lucid1
released
maverick
dne
natty
dne
oneiric
dne
linux-lts-backport-natty
hardy
dne
lucid
Fixed 2.6.38-11.49~lucid1
released
maverick
dne
natty
dne
oneiric
dne
linux-lts-backport-oneiric
hardy
dne
lucid
not-affected
maverick
dne
natty
dne
oneiric
dne
linux-mvl-dove
hardy
dne
lucid
Fixed 2.6.32-219.37
released
maverick
Fixed 2.6.32-419.37
released
natty
dne
oneiric
dne
linux-ti-omap4
hardy
dne
lucid
dne
maverick
Fixed 2.6.35-903.23
released
natty
Fixed 2.6.38-1209.15
released
oneiric
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
ecryptfs-utils-111
suse enterprise desktop 15
2.31
fixed
suse enterprise desktop 15 SP1
2.31
fixed
suse enterprise desktop 15 SP2
2.31
fixed
suse enterprise desktop 15 SP3
2.31
fixed
suse enterprise desktop 15 SP4
2.31
fixed
suse enterprise desktop 15 SP5
2.31
fixed
suse enterprise sap 15
2.31
fixed
suse enterprise sap 15 SP1
2.31
fixed
suse enterprise sap 15 SP2
2.31
fixed
suse enterprise sap 15 SP3
2.31
fixed
suse enterprise sap 15 SP4
2.31
fixed
suse enterprise sap 15 SP5
2.31
fixed
suse enterprise server 15
2.31
fixed
suse enterprise server 15 SP1
2.31
fixed
suse enterprise server 15 SP2
2.31
fixed
suse enterprise server 15 SP3
2.31
fixed
suse enterprise server 15 SP4
2.31
fixed
suse enterprise server 15 SP5
2.31
fixed
ecryptfs-utils-devel-111
suse enterprise desktop 15
2.31
fixed
suse enterprise desktop 15 SP1
2.31
fixed
suse enterprise desktop 15 SP2
2.31
fixed
suse enterprise desktop 15 SP3
2.31
fixed
suse enterprise desktop 15 SP4
2.31
fixed
suse enterprise desktop 15 SP5
2.31
fixed
suse enterprise sap 15
2.31
fixed
suse enterprise sap 15 SP1
2.31
fixed
suse enterprise sap 15 SP2
2.31
fixed
suse enterprise sap 15 SP3
2.31
fixed
suse enterprise sap 15 SP4
2.31
fixed
suse enterprise sap 15 SP5
2.31
fixed
suse enterprise server 15
2.31
fixed
suse enterprise server 15 SP1
2.31
fixed
suse enterprise server 15 SP2
2.31
fixed
suse enterprise server 15 SP3
2.31
fixed
suse enterprise server 15 SP4
2.31
fixed
suse enterprise server 15 SP5
2.31
fixed
libecryptfs1-111
suse enterprise desktop 15
2.31
fixed
suse enterprise desktop 15 SP1
2.31
fixed
suse enterprise desktop 15 SP2
2.31
fixed
suse enterprise desktop 15 SP3
2.31
fixed
suse enterprise desktop 15 SP4
2.31
fixed
suse enterprise desktop 15 SP5
2.31
fixed
suse enterprise sap 15
2.31
fixed
suse enterprise sap 15 SP1
2.31
fixed
suse enterprise sap 15 SP2
2.31
fixed
suse enterprise sap 15 SP3
2.31
fixed
suse enterprise sap 15 SP4
2.31
fixed
suse enterprise sap 15 SP5
2.31
fixed
suse enterprise server 15
2.31
fixed
suse enterprise server 15 SP1
2.31
fixed
suse enterprise server 15 SP2
2.31
fixed
suse enterprise server 15 SP3
2.31
fixed
suse enterprise server 15 SP4
2.31
fixed
suse enterprise server 15 SP5
2.31
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
kernel
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-bootwrapper
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-debug
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-debug-devel
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-devel
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-doc
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-firmware
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-headers
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-kdump
RHEL 6
0:2.6.32-131.17.1.el6
fixed
kernel-kdump-devel
RHEL 6
0:2.6.32-131.17.1.el6
fixed
perf
RHEL 6
0:2.6.32-131.17.1.el6
fixed
Common Weakness Enumeration