CVE-2014-1425
published 2015-01-07CVE-2014-1425: cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.36%
28.2th percentile
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| linuxcontainers | cgmanager | — | — |
| linuxcontainers | cgmanager | >= 0 < 0.24-0ubuntu7.1 | 0.24-0ubuntu7.1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cwq-36p8-jfpc: cmanager 0
ghsa_unreviewed·2022-05-17
CVE-2014-1425 [LOW] GHSA-3cwq-36p8-jfpc: cmanager 0
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
OSV
CVE-2014-1425: cmanager 0
osv·2015-01-06·CVSS 2.1
CVE-2014-1425 [LOW] CVE-2014-1425: cmanager 0
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
Ubuntu
cgmanager vulnerability
vendor_ubuntu·2015-01-06
CVE-2014-1425 cgmanager vulnerability
Title: cgmanager vulnerability
Summary: cgmanager could be made to expose sensitive information or devices to
containers running on the system.
Serge Hallyn discovered that cgmanager did not consistently enforce
proper nesting when modifying cgroup properties. A local attacker in a
privileged container could use this to set cgroup values for all cgroups.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-01-07
Published