PT-2018-3455 · Linux Containers+3 · Lxc+3

Matthias Gerstner

·

Published

2017-09-07

·

Updated

2025-04-10

·

CVE-2018-6556

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: LXC versions 2.0.9 and above LXC versions 3.0.0 and above, prior to 3.0.2
Description: The issue is related to the lxc-user-nic when deleting a network interface, which unconditionally opens a user-provided path. This can be used by an unprivileged user to check for the existence of a path they wouldn't otherwise be able to reach. It may also trigger side effects by causing a read-only open of special kernel files, such as ptmx, proc, and sys.
Recommendations: For LXC versions 2.0.9 and above, update to a version prior to the affected range or apply a patch if available. For LXC versions 3.0.0 and above, prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the lxc-user-nic functionality to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2154
ALT-PU-2018-2293
BDU:2020-01714
CVE-2018-6556
OPENSUSE-SU-2018_2316-1
OPENSUSE-SU-2019:1227-1
OPENSUSE-SU-2019:1230-1
OPENSUSE-SU-2019:1275-1
OPENSUSE-SU-2019_1275-1
OPENSUSE-SU-2019_1481-1
OPENSUSE-SU-2024:11030-1
USN-3730-1

Affected Products

Alt Linux
Lxc
Suse
Ubuntu