CVE-2017-5985
published 2017-03-14CVE-2017-5985: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those…
PriorityP410low3.3CVSS 3.0
AVLACLPRLUINSUCNILAN
EPSS
0.34%
25.9th percentile
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lxc | < lxc 1:2.0.7-2 (bookworm) | lxc 1:2.0.7-2 (bookworm) |
| linuxcontainers | lxc | <= 1.0.9 | — |
| linuxcontainers | lxc | >= 0 < 1:2.0.7-2 | 1:2.0.7-2 |
| linuxcontainers | lxc | >= 0 < 1:2.0.7-2 | 1:2.0.7-2 |
| linuxcontainers | lxc | >= 0 < 1:2.0.7-2 | 1:2.0.7-2 |
| linuxcontainers | lxc | >= 0 < 1:2.0.7-2 | 1:2.0.7-2 |
| linuxcontainers | lxc | 2.0.0 – 2.0.6 | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LXC vulnerability
vendor_ubuntu·2017-03-09
CVE-2017-5985 LXC vulnerability
Title: LXC vulnerability
Summary: LXC could be made to create arbitrary virtual network interfaces as an
administrator.
Jann Horn discovered that LXC incorrectly verified permissions when creating
virtual network interfaces. A local attacker could possibly use this issue to
create virtual network interfaces in network namespaces that they do not own.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2017-5985: lxc - lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet all...
vendor_debian·2017·CVSS 3.3
CVE-2017-5985 [LOW] CVE-2017-5985: lxc - lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet all...
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
Scope: local
bookworm: resolved (fixed in 1:2.0.7-2)
bullseye: resolved (fixed in 1:2.0.7-2)
forky: resolved (fixed in 1:2.0.7-2)
sid: resolved (fixed in 1:2.0.7-2)
trixie: resolved (fixed in 1:2.0.7-2)
GHSA
GHSA-wxh2-mqg8-qff6: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name o
ghsa_unreviewed·2022-05-13
CVE-2017-5985 [LOW] CWE-862 GHSA-wxh2-mqg8-qff6: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name o
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
OSV
CVE-2017-5985: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name o
osv·2017-03-14·CVSS 3.3
CVE-2017-5985 [LOW] CVE-2017-5985: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name o
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-6]
bugzilla·2017-03-13·CVSS 3.3
CVE-2017-5985 [LOW] CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-6]
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the
Bugzilla
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-7]
bugzilla·2017-03-13·CVSS 3.3
CVE-2017-5985 [LOW] CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-7]
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the
Bugzilla
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership
bugzilla·2017-03-13·CVSS 3.3
CVE-2017-5985 [LOW] CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership
It was found that lxc-user-nic could potentially have been tricked into operating on a network namespace over which the caller did not hold privilege.
References:
http://seclists.org/oss-sec/2017/q1/576
https://lists.linuxcontainers.org/pipermail/lxc-users/2017-March/012925.html
Upstream bug:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1654676
Upstream patch:
https://github.com/lxc/lxc/commit/16af238036a5464ae8f2420ed3af214f0de875f9
Discussion:
Created lxc tracking bugs for this issue:
Affects: epel-6 [bug 1431559]
Affects: epel-7 [bug 1431558]
---
lxc-1.0.10-2.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
---
lxc
Unit42
Rootless Containers: The Next Trend in Container Security
blogs_unit42·2020-05-26
Rootless Containers: The Next Trend in Container Security
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## Rootless Containers: The Next Trend in Container Security
Aviv Sasson
Published: May 26, 2020
Cloud Cybersecurity Research
Threat Research
Podman LXC Container Security
Rootless Containers
Slirp
## Executive Summary
As cloud computing evolves, containers continue to become more and more popular. New solutions and ideas to the way we implement containers are being introduced. One of these new ideas is rootless containers.
Rootless containers is a new concept of containers that don’t require root privileges in order to formulate. Many solutions have been proposed to overcome the technological challenges of creating a container with an unprivileged user, some of them are still under development and some ar
Unit42
Rootless Containers: The Next Trend in Container Security
blogs_unit42·2020-05-26
Rootless Containers: The Next Trend in Container Security
## Executive Summary
As cloud computing evolves, containers continue to become more and more popular. New solutions and ideas to the way we implement containers are being introduced. One of these new ideas is rootless containers.
Rootless containers is a new concept of containers that don’t require root privileges in order to formulate. Many solutions have been proposed to overcome the technological challenges of creating a container with an unprivileged user, some of them are still under development and some are production-ready. While rootless containers present some advantages, mainly from a security perspective, they are still in their early stages.
In this post, Unit 42 researcher Aviv Sasson reviews the internals of rootless containers. Aviv also presents a vulnerability he found
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttp://www.openwall.com/lists/oss-security/2017/03/09/4http://www.securityfocus.com/bid/96777http://www.ubuntu.com/usn/USN-3224-1https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1654676https://github.com/lxc/lxc/commit/16af238036a5464ae8f2420ed3af214f0de875f9https://lists.linuxcontainers.org/pipermail/lxc-devel/2017-March/015535.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttp://www.openwall.com/lists/oss-security/2017/03/09/4http://www.securityfocus.com/bid/96777http://www.ubuntu.com/usn/USN-3224-1https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1654676https://github.com/lxc/lxc/commit/16af238036a5464ae8f2420ed3af214f0de875f9https://lists.linuxcontainers.org/pipermail/lxc-devel/2017-March/015535.html
2017-03-14
Published