cbcvebase.
CVE-2015-1335
published 2015-10-01

CVE-2015-1335: lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount…

PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.46%
37.0th percentile
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlxc< lxc 1:1.0.8-1 (bookworm)lxc 1:1.0.8-1 (bookworm)
linuxcontainerslxc<= 1.0.7
linuxcontainerslxc
linuxcontainerslxc
linuxcontainerslxc
linuxcontainerslxc
linuxcontainerslxc>= 0 < 1:1.0.8-11:1.0.8-1
linuxcontainerslxc>= 0 < 1:1.0.8-11:1.0.8-1
linuxcontainerslxc>= 0 < 1:1.0.8-11:1.0.8-1
linuxcontainerslxc>= 0 < 1:1.0.8-11:1.0.8-1

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.