CVE-2018-6556
published 2018-08-10CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to…
PriorityP411low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.35%
26.8th percentile
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | lxc | < lxc 1:5.0.2-1 (bookworm) | lxc 1:5.0.2-1 (bookworm) |
| debian | lxc | < lxc 1:2.0.9-6.1 (bookworm) | lxc 1:2.0.9-6.1 (bookworm) |
| linuxcontainers | lxc | <= 5.0.1 | — |
| linuxcontainers | lxc | >= 0 < 1:2.0.9-6.1 | 1:2.0.9-6.1 |
| linuxcontainers | lxc | >= 0 < 1:4.0.6-2+deb11u2 | 1:4.0.6-2+deb11u2 |
| linuxcontainers | lxc | >= 0 < 1:2.0.9-6.1 | 1:2.0.9-6.1 |
| linuxcontainers | lxc | >= 0 < 1:5.0.2-1 | 1:5.0.2-1 |
| linuxcontainers | lxc | >= 0 < 1:2.0.9-6.1 | 1:2.0.9-6.1 |
| linuxcontainers | lxc | >= 0 < 1:5.0.2-1 | 1:5.0.2-1 |
| linuxcontainers | lxc | >= 0 < 1:2.0.9-6.1 | 1:2.0.9-6.1 |
| linuxcontainers | lxc | >= 0 < 1:5.0.2-1 | 1:5.0.2-1 |
| linuxcontainers | lxc | 2.0.0 – 2.0.9 | — |
| linuxcontainers | lxc | >= 3.0.0 < 3.0.2 | 3.0.2 |
| opensuse | leap | — | — |
| suse | caas_platform | — | — |
| suse | caas_platform | — | — |
| suse | openstack_cloud | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-47952: lxc - lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local ...
vendor_debian·2022·CVSS 3.3
CVE-2022-47952 [LOW] CVE-2022-47952: lxc - lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local ...
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.
Scope: local
bookworm: resolved (fixed in 1:5.0.2-1)
bullseye: resolved (fixed in 1:4.0.6-2+deb11u2)
forky: resolved (fixed in 1:5.0.2-1)
sid: resolved
Ubuntu
LXC vulnerability
vendor_ubuntu·2018-08-06
CVE-2018-6556 LXC vulnerability
Title: LXC vulnerability
Summary: LXC would allow unintended access to files.
Matthias Gerstner discovered that LXC incorrectly handled the lxc-user-nic
utility. A local attacker could possibly use this issue to open arbitrary
files.
Instructions: After a standard system update you need to restart LXC containers to make
all the necessary changes.
Debian
CVE-2018-6556: lxc - lxc-user-nic when asked to delete a network interface will unconditionally open ...
vendor_debian·2018·CVSS 3.3
CVE-2018-6556 [LOW] CVE-2018-6556: lxc - lxc-user-nic when asked to delete a network interface will unconditionally open ...
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
Scope: local
bookworm: resolved (fixed in 1:2.0.9-6.1)
bullseye: resolved (fixed in 1:2.0.9-6.1)
forky: resolved (fixed in 1:2.0.9-6.1)
sid: resolved (fixed in 1:2.0.9-6.1)
trixie: resolved (fixed in 1:2.0.9-6.1)
GHSA
GHSA-qv29-rjwj-jjrm: lxc-user-nic in lxc through 5
ghsa_unreviewed·2023-01-01·CVSS 3.3
CVE-2022-47952 [LOW] CWE-203 GHSA-qv29-rjwj-jjrm: lxc-user-nic in lxc through 5
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.
OSV
CVE-2022-47952: lxc-user-nic in lxc through 5
osv·2023-01-01·CVSS 3.3
CVE-2022-47952 [LOW] CVE-2022-47952: lxc-user-nic in lxc through 5
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.
GHSA
GHSA-xg68-6jxg-5w7p: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path
ghsa_unreviewed·2022-05-14
CVE-2018-6556 [LOW] GHSA-xg68-6jxg-5w7p: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
OSV
CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path
osv·2018-08-10·CVSS 3.3
CVE-2018-6556 [LOW] CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
No detection rules found.
No public exploits indexed.
Unit42
Rootless Containers: The Next Trend in Container Security
blogs_unit42·2020-05-26
Rootless Containers: The Next Trend in Container Security
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## Rootless Containers: The Next Trend in Container Security
Aviv Sasson
Published: May 26, 2020
Cloud Cybersecurity Research
Threat Research
Podman LXC Container Security
Rootless Containers
Slirp
## Executive Summary
As cloud computing evolves, containers continue to become more and more popular. New solutions and ideas to the way we implement containers are being introduced. One of these new ideas is rootless containers.
Rootless containers is a new concept of containers that don’t require root privileges in order to formulate. Many solutions have been proposed to overcome the technological challenges of creating a container with an unprivileged user, some of them are still under development and some ar
Unit42
Rootless Containers: The Next Trend in Container Security
blogs_unit42·2020-05-26
Rootless Containers: The Next Trend in Container Security
## Executive Summary
As cloud computing evolves, containers continue to become more and more popular. New solutions and ideas to the way we implement containers are being introduced. One of these new ideas is rootless containers.
Rootless containers is a new concept of containers that don’t require root privileges in order to formulate. Many solutions have been proposed to overcome the technological challenges of creating a container with an unprivileged user, some of them are still under development and some are production-ready. While rootless containers present some advantages, mainly from a security perspective, they are still in their early stages.
In this post, Unit 42 researcher Aviv Sasson reviews the internals of rootless containers. Aviv also presents a vulnerability he found
Bugzilla
CVE-2018-6556 lxc: lxc-user-nic allows for open() of arbitrary paths
bugzilla·2018-08-13·CVSS 3.3
CVE-2018-6556 [LOW] CVE-2018-6556 lxc: lxc-user-nic allows for open() of arbitrary paths
CVE-2018-6556 lxc: lxc-user-nic allows for open() of arbitrary paths
A flaw was found in lxc-user-nic 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2. . When asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys).
References:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1783591
https://bugzilla.suse.com/show_bug.cgi?id=988348
Upstream Patches:
- stable-2.0: https://github.com/lxc/lxc/commit/5eb45428b312e978fb9e294dde16efb14dd9fa4d
- stable-3.0: https://githu
Bugzilla
CVE-2018-6556 lxc: lxc-user-nic allows for open() of arbitrary paths [fedora-all]
bugzilla·2018-08-13·CVSS 3.3
CVE-2018-6556 [LOW] CVE-2018-6556 lxc: lxc-user-nic allows for open() of arbitrary paths [fedora-all]
CVE-2018-6556 lxc: lxc-user-nic allows for open() of arbitrary paths [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00091.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttps://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1783591https://bugzilla.suse.com/show_bug.cgi?id=988348https://security.gentoo.org/glsa/201808-02https://usn.ubuntu.com/usn/usn-3730-1http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00091.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttps://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1783591https://bugzilla.suse.com/show_bug.cgi?id=988348https://security.gentoo.org/glsa/201808-02https://usn.ubuntu.com/usn/usn-3730-1
2018-08-10
Published