CVE-2016-8649

CWE-2649 documents7 sources
Severity
9.1CRITICAL
EPSS
2.2%
top 15.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateMay 14

Description

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages3 packages

CVEListV5lxc_before_1.0.9_and_2.x_before_2.0.6LXC before 1.0.9 and 2.x before 2.0.6
NVDlinuxcontainers/lxc2.0.02.0.6+1
Debianlxc< 1:2.0.6-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vp8j-2cg9-6pvv: lxc-attach in LXC before 12022-05-14
CVEList
CVE-2016-8649: lxc-attach in LXC before 12017-05-01
OSV
CVE-2016-8649: lxc-attach in LXC before 12017-05-01

📋Vendor Advisories

2
Ubuntu
LXC vulnerability2016-11-23
Debian
CVE-2016-8649: lxc - lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of...2016

💬Community

3
Bugzilla
CVE-2016-8649 lxc: lxc-attach to malicious container allows access to host [fedora-all]2016-11-24
Bugzilla
CVE-2016-8649 lxc: lxc-attach to malicious container allows access to host [epel-all]2016-11-24
Bugzilla
CVE-2016-8649 lxc: lxc-attach to malicious container allows access to host2016-11-24
CVE-2016-8649 (CRITICAL CVSS 9.1) | lxc-attach in LXC before 1.0.9 and | cvebase.io