cbcvebase.
CVE-2018-6556
published 2018-08-10

CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to…

low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianlxc< lxc 1:5.0.2-1 (bookworm)lxc 1:5.0.2-1 (bookworm)
debianlxc< lxc 1:2.0.9-6.1 (bookworm)lxc 1:2.0.9-6.1 (bookworm)
linuxcontainerslxc<= 5.0.1
linuxcontainerslxc>= 0 < 1:2.0.9-6.11:2.0.9-6.1
linuxcontainerslxc>= 0 < 1:4.0.6-2+deb11u21:4.0.6-2+deb11u2
linuxcontainerslxc>= 0 < 1:2.0.9-6.11:2.0.9-6.1
linuxcontainerslxc>= 0 < 1:5.0.2-11:5.0.2-1
linuxcontainerslxc>= 0 < 1:2.0.9-6.11:2.0.9-6.1
linuxcontainerslxc>= 0 < 1:5.0.2-11:5.0.2-1
linuxcontainerslxc>= 0 < 1:2.0.9-6.11:2.0.9-6.1
linuxcontainerslxc>= 0 < 1:5.0.2-11:5.0.2-1
linuxcontainerslxc2.0.0 – 2.0.9
linuxcontainerslxc>= 3.0.0 < 3.0.23.0.2
opensuseleap
susecaas_platform
susecaas_platform
suseopenstack_cloud
susesuse_linux_enterprise_server

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW