attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lxc | Jul 30, 2024 | Aug 12, 2015 |
| Oracle_linux | — | Upgrade lxc-libsUpgrade lxcUpgrade lxc-devel | Oct 16, 2024 | Aug 12, 2015 |
| Suse | — | Upgrade lxcfs-hooks-lxcUpgrade lxc-develUpgrade lxcUpgrade lxc-debugsourceUpgrade liblxc1-debuginfoUpgrade lxcfs-debugsourceUpgrade liblxc-develUpgrade liblxc1Upgrade lxc-debuginfoUpgrade lxcfsUpgrade pam_cgfs-debuginfoUpgrade lxc-bash-completionUpgrade lxcfs-debuginfoUpgrade pam_cgfs | Dec 18, 2015 | Jul 30, 2015 |
| Ubuntu | — | Upgrade liblxc1Upgrade lxc | Nov 8, 2024 | Aug 12, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub