CVE-2014-1425: Low severity linuxcontainers Cgmanager vulnerability
Published Jan 7, 2015
·Updated
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
Affected Software
3 affected components
linuxcontainers Cgmanager=0.32
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Event History
Jan 7, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1425?
CVE-2014-1425 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2014-1425?
To fix CVE-2014-1425, upgrade cgmanager to version 0.33 or later, or remove cgmanager if it's not needed.
3
Who is affected by CVE-2014-1425?
CVE-2014-1425 affects local users of cgmanager version 0.32 on Ubuntu Linux 14.04 and 14.10.
4
What are the implications of CVE-2014-1425?
CVE-2014-1425 allows local users to modify cgroup properties, potentially impacting system performance and security.
5
Is there a workaround for CVE-2014-1425?
A temporary workaround for CVE-2014-1425 includes restricting local user access to cgroup settings until a patch is applied.