CVE-2015-1334: Medium severity linuxcontainers Lxc vulnerability
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1334?
CVE-2015-1334 has been assigned a moderate severity rating due to its ability to allow local users to escape confinement mechanisms.
How do I fix CVE-2015-1334?
To fix CVE-2015-1334, upgrade LXC to version 1.1.3 or later, where the vulnerability is resolved.
What systems are affected by CVE-2015-1334?
CVE-2015-1334 affects LXC versions prior to 1.1.3, allowing local users within containers to exploit confinement weaknesses.
What types of confinement are compromised by CVE-2015-1334?
CVE-2015-1334 can compromise AppArmor and SELinux confinement through improper use of the proc filesystem.
Is CVE-2015-1334 an exploit for remote attacks?
CVE-2015-1334 is not a remote attack exploit, as it requires local access to the container to be effective.