Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2016-8649

Published: 23 November 2016

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

Priority

Medium

CVSS 3 base score: 9.1

Status

Package Release Status
lxc
Launchpad, Ubuntu, Debian
precise Does not exist
(precise was needs-triage)
trusty Not vulnerable
(trusty was released [1.0.8-0ubuntu0.4])
upstream Needed

xenial
Released (2.0.5-0ubuntu1~ubuntu16.04.3)
yakkety
Released (2.0.5-0ubuntu1.2)
zesty
Released (2.0.5-0ubuntu4)