CVE-2017-5985

Severity
3.3LOW
EPSS
0.1%
top 74.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 13

Description

lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDlinuxcontainers/lxc2.0.02.0.6+1
Debianlxc< 1:2.0.7-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wxh2-mqg8-qff6: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name o2022-05-13
OSV
CVE-2017-5985: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name o2017-03-14
CVEList
CVE-2017-5985: lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name o2017-03-14

📋Vendor Advisories

2
Ubuntu
LXC vulnerability2017-03-09
Debian
CVE-2017-5985: lxc - lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet all...2017

💬Community

3
Bugzilla
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-6]2017-03-13
Bugzilla
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership [epel-7]2017-03-13
Bugzilla
CVE-2017-5985 lxc: lxc-user-nic didn't verify network namespace ownership2017-03-13
CVE-2017-5985 (LOW CVSS 3.3) | lxc-user-nic in Linux Containers (L | cvebase.io