Total vulnerabilities in the database
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
Software | From | Fixed in |
---|---|---|
canonical / ubuntu_linux | 18.04 | 18.04.x |
linuxcontainers / lxc | 2.0.0 | 2.0.9.x |
linuxcontainers / lxc | 3.0.0 | 3.0.2 |
suse / suse_linux_enterprise_server | 11-sp4 | 11-sp4.x |
suse / openstack_cloud | 6 | 6.x |
suse / suse_linux_enterprise_server | 11-sp3 | 11-sp3.x |
suse / caas_platform | 1.0 | 1.0.x |
suse / caas_platform | 2.0 | 2.0.x |
opensuse / leap | 15.0 | 15.0.x |