CVE-2016-8649
Dashboard / Vulnerabilities / CVE-2016-8649
Summary:
Details: lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.
References: http://www.securityfocus.com/bid/94498, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845465, https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1639345, https://security-tracker.debian.org/tracker/CVE-2016-8649, https://bugzilla.redhat.com/show_bug.cgi?id=1398242, https://github.com/lxc/lxc/commit/81f466d05f2a89cb4f122ef7f593ff3f279b165c
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
lxc-2.0.5
lxc-2.0.4
lxc-2.0.3
lxc-2.0.2
lxc-2.0.1
lxc-2.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
