lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lxc | Jul 30, 2024 | May 1, 2017 |
| Suse | — | Upgrade lxc-debugsourceUpgrade lxc-debuginfoUpgrade lxc-develUpgrade lxc | Dec 19, 2016 | Nov 23, 2016 |
| Ubuntu | — | Upgrade liblxc1Upgrade lxcUpgrade lxc1 | Nov 23, 2016 | Nov 23, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub