CVE-2015-1335: High severity linuxcontainers Lxc vulnerability
Published Oct 1, 2015
·Updated
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
Affected Software
7 affected components
linuxcontainers Lxc<=1.0.7
linuxcontainers Lxc=1.1.0
linuxcontainers Lxc=1.1.1
linuxcontainers Lxc=1.1.2
linuxcontainers Lxc=1.1.3
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Remediation
Event History
Oct 1, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1335?
CVE-2015-1335 is rated as a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2015-1335?
To resolve CVE-2015-1335, upgrade LXC to version 1.0.8 or higher, or 1.1.4 or higher.
3
Which versions of LXC are affected by CVE-2015-1335?
CVE-2015-1335 affects LXC versions before 1.0.8 and all 1.1.x versions prior to 1.1.4.
4
Can CVE-2015-1335 be exploited by local users?
Yes, CVE-2015-1335 can be exploited by local container administrators to escape AppArmor confinement.
5
What impact does CVE-2015-1335 have on system security?
CVE-2015-1335 may allow a local attacker to gain elevated privileges and compromise the security of the host system.