PT-2015-5218 · Linux Containers+3 · Lxc+3
Roman Fiedler
·
Published
2015-07-22
·
Updated
2024-06-15
·
CVE-2015-1334
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
LXC versions 1.1.2 and earlier
Description
The issue allows local container users to escape AppArmor or SELinux confinement. This is achieved by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.
Recommendations
For LXC versions 1.1.2 and earlier, consider disabling the use of the proc filesystem in containers until a patch is available. Restrict access to the attach.c module to minimize the risk of exploitation. Avoid using crafted AppArmor profiles or SELinux labels in the affected containers.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Lxc
Suse
Ubuntu