CVE-2015-8222
published 2015-11-17CVE-2015-8222: The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.38%
30.9th percentile
The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | lxd | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_debian4.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-8222: lxd - The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubu...
vendor_debian·2015·CVSS 4.6
CVE-2015-8222 [MEDIUM] CVE-2015-8222: lxd - The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubu...
The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.
Scope: local
bookworm: resolved
trixie: resolved
GHSA
GHSA-5rhm-g244-h7c9: The lxd-unix
ghsa_unreviewed·2022-05-17
CVE-2015-8222 [MEDIUM] GHSA-5rhm-g244-h7c9: The lxd-unix
The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-17
Published