The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxattr call involving a tmpfs filesystem, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7097.
3.11.0-12.196.5.0-9.94.13.0-16.195.13.0-19.194.2.0-16.194.2.0-17.214.2.0-19.234.3.0-1.104.3.0-2.114.3.0-5.164.3.0-6.174.3.0-7.184.4.0-10.254.4.0-11.26+35 more4.4.0-67.885.3.0-18.195.3.0-24.265.4.0-9.124.4.0-1001.104.4.0-1003.124.4.0-1004.134.4.0-1007.164.4.0-1009.184.4.0-1002.25.13.0-1005.66.5.0-1008.8Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:LI:LA:NCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N