GHSA-8mpq-fmr3-6jxv
Dashboard / Vulnerabilities / GHSA-8mpq-fmr3-6jxv
GHSA-8mpq-fmr3-6jxv
Summary: LXD vulnerable to Race Condition
Details: LXD before version 0.19-0ubuntu5 `doUidshiftIntoContainer()` has an unsafe `Chmod()` call that races against the stat in the `Filepath.Walk()` function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice. ### Specific Go Packages Affected github.com/lxc/lxd/shared
References: https://nvd.nist.gov/vuln/detail/CVE-2015-1340, https://github.com/lxc/lxd/pull/1189, https://github.com/lxc/lxd/commit/19c6961cc1012c8a529f20807328a9357f5034f4, https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1502270, https://github.com/lxc/lxd, https://pkg.go.dev/vuln/GO-2021-0071
Affected packages
Package
Name: github.com/lxc/lxd
Purl: pkg:golang/github.com/lxc/lxd
Affected ranges
Type: SEMVER
Events:
