Candidate: CVE-2007-4849 References: http://git.infradead.org/?p=mtd-2.6.git;a=commitdiff;h=9ed437c50d89eabae763dd422579f73fdebf288d http://lists.infradead.org/pipermail/linux-mtd-cvs/2007-August/005897.html http://dev.laptop.org/ticket/2732 Description: JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related to "legacy modes" and an inconsistency between dentry permissions and inode permissions. Ubuntu-Description: Notes: jmm> ACL support was introduced in 2.6.17 with commit aa98d7cf59b5b0764d3502662053489585faf2fe, marking jmm> earlier Debian releases as N/A Bugs: upstream: released (2.6.23-rc4) linux-2.6: needed 2.6.18-etch-security: released (2.6.18.dfsg.1-13etch3) [bugfix/jffs2-ACL-vs-mode-handling.patch] 2.6.8-sarge-security: N/A 2.4.27-sarge-security: N/A 2.6.15-dapper-security: N/A 2.6.17-edgy-security: needed 2.6.20-feisty-security: needed