First published: Wed Jan 07 2015(Updated: )
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Containers cgmanager | =0.32 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1425 has been classified as a medium severity vulnerability.
To fix CVE-2014-1425, upgrade cgmanager to version 0.33 or later, or remove cgmanager if it's not needed.
CVE-2014-1425 affects local users of cgmanager version 0.32 on Ubuntu Linux 14.04 and 14.10.
CVE-2014-1425 allows local users to modify cgroup properties, potentially impacting system performance and security.
A temporary workaround for CVE-2014-1425 includes restricting local user access to cgroup settings until a patch is applied.