MGASA-2019-0087
Dashboard / Vulnerabilities / MGASA-2019-0087
Summary: Updated lxc packages fix security vulnerability
Details: LXC allows attackers to overwrite the host LXC binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: a new container with an attacker-controlled image, or an existing container, to which the attacker previously had write access. This occurs because of file-descriptor mishandling, related to /proc/self/exe. This attack is only possible with privileged containers since it requires root privilege on the host to overwrite the binary.
References: https://advisories.mageia.org/MGASA-2019-0087.html, https://bugs.mageia.org/show_bug.cgi?id=24350, https://www.openwall.com/lists/oss-security/2019/02/11/2
Affected packages
Package
Name: lxc
Purl: pkg:rpm/mageia/lxc?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
