CVE-2016-1582
published 2016-06-09CVE-2016-1582: LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary…
PriorityP424medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.35%
27.1th percentile
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | lxd | — | — |
| canonical | lxd | >= 0 < 2.0.2-0ubuntu1~16.04.1 | 2.0.2-0ubuntu1~16.04.1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | lxd | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
lxd vulnerabilities
osv·2016-05-31·CVSS 5.5
CVE-2016-1581 [MEDIUM] lxd vulnerabilities
lxd vulnerabilities
Robie Basak discovered that LXD incorrectly set permissions when setting up
a loop based ZFS pool. A local attacker could use this issue to copy and
read the data of any LXD container. (CVE-2016-1581)
Robie Basak discovered that LXD incorrectly set permissions when switching
an unprivileged container into privileged mode. A local attacker could use
this issue to access any world readable path in the container directory,
including setuid binaries. (CVE-2016-1582)
OSV
CVE-2016-1582: LXD before 2
osv·2016-05-31·CVSS 5.5
CVE-2016-1582 [MEDIUM] CVE-2016-1582: LXD before 2
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
Ubuntu
LXD vulnerabilities
vendor_ubuntu·2016-05-31·CVSS 5.5
CVE-2016-1581 [MEDIUM] LXD vulnerabilities
Title: LXD vulnerabilities
Summary: Several security issues were fixed in LXD.
Robie Basak discovered that LXD incorrectly set permissions when setting up
a loop based ZFS pool. A local attacker could use this issue to copy and
read the data of any LXD container. (CVE-2016-1581)
Robie Basak discovered that LXD incorrectly set permissions when switching
an unprivileged container into privileged mode. A local attacker could use
this issue to access any world readable path in the container directory,
including setuid binaries. (CVE-2016-1582)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2016-1582: lxd - LXD before 2.0.2 does not properly set permissions when switching an unprivilege...
vendor_debian·2016·CVSS 5.5
CVE-2016-1582 [MEDIUM] CVE-2016-1582: lxd - LXD before 2.0.2 does not properly set permissions when switching an unprivilege...
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
Scope: local
bookworm: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-06-09
Published