VulnerabilityModified
CVE-2015-1342
LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.
MEDIUM 4.6EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- canonical/ubuntu linux · canonical/lxcfs
- Source
- security@ubuntu.com
References
- http://www.ubuntu.com/usn/USN-2813-1
- https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1508481Exploit
- https://github.com/lxc/lxcfs/commit/a8b6c3e0537e90fba3c55910fd1b7229d54a60a7
- http://www.ubuntu.com/usn/USN-2813-1
- https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1508481Exploit
- https://github.com/lxc/lxcfs/commit/a8b6c3e0537e90fba3c55910fd1b7229d54a60a7
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.