GO-2021-0071

    Dashboard / Vulnerabilities / GO-2021-0071

    GO-2021-0071

    Published: 14 Apr 2021Last Modified: 3 Jun 2024

    Summary: Race condition in github.com/lxc/lxd

    Details: A race between chown and chmod operations during a container filesystem shift may allow a user who can modify the filesystem to chmod an arbitrary path of their choice, rather than the expected path.

    Affected packages

    Package

    Name: github.com/lxc/lxd

    Purl: pkg:golang/github.com/lxc/lxd

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.0.0-20151004155856-19c6961cc101

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2021-0071 | CVE-DB