An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations, aka CID-ff002b30181d.
{ "binaries": [ { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-buildinfo-5.3.0-1018-gke" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-gke-5.3-headers-5.3.0-1018" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-gke-5.3-tools-5.3.0-1018" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-headers-5.3.0-1018-gke" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-image-unsigned-5.3.0-1018-gke" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-image-unsigned-5.3.0-1018-gke-dbgsym" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-modules-5.3.0-1018-gke" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-modules-extra-5.3.0-1018-gke" }, { "binary_version": "5.3.0-1018.19~18.04.1", "binary_name": "linux-tools-5.3.0-1018-gke" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-buildinfo-5.3.0-1023-raspi2" }, { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-headers-5.3.0-1023-raspi2" }, { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-image-5.3.0-1023-raspi2" }, { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-image-5.3.0-1023-raspi2-dbgsym" }, { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-modules-5.3.0-1023-raspi2" }, { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-raspi2-5.3-headers-5.3.0-1023" }, { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-raspi2-5.3-tools-5.3.0-1023" }, { "binary_version": "5.3.0-1023.25~18.04.1", "binary_name": "linux-tools-5.3.0-1023-raspi2" } ], "availability": "No subscription required" }