CVE-2016-3096: High severity red hat fedora vulnerability

Published Mar 31, 2016
·
Updated

A vulnerability in lxccontainer, ansible module, was found allowing to get root inside the container. The problem is in the createscript function, which tries to write to /opt/.lxc-attach-script inside of the container. If the attacker can write to /opt/.lxc-attach-script before that, he can overwrite arbitrary files or execute commands as root.

Other sources

The createscript function in the lxccontainer module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archivepath directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.

GitHub

The createscript function in the lxccontainer module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archivepath directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.

MITRE

Affected Software

8 affected componentsFixes available
pip/ansible>=2.0.0.0<=2.0.1.0
2.0.2.0
pip/ansible<=1.9.6.0
1.9.6.1
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Fedoraproject Fedora=24
redhat ansible<=1.9.6
redhat ansible=2.0
redhat ansible=2.0.1

Event History

Mar 31, 2016
Data Sourced
via Red Hat·05:00 PM
DescriptionSeverityAffected Software
Jun 3, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Oct 10, 2018
Advisory Published
via GitHub·05:23 PM

Frequently Asked Questions

1

What is the severity of CVE-2016-3096?

CVE-2016-3096 is considered a critical vulnerability due to its potential to allow unauthorized root access inside containers.

2

How do I fix CVE-2016-3096?

To fix CVE-2016-3096, upgrade the ansible package to version 2.0.2.0 or 1.9.6.1 or later.

3

What versions of ansible are affected by CVE-2016-3096?

Affected versions of ansible include 1.9.6 and earlier, and 2.0.1.0 and earlier.

4

What products are impacted by CVE-2016-3096?

CVE-2016-3096 impacts the ansible modules within Fedora versions 22, 23, and 24.

5

What is the exploit method for CVE-2016-3096?

The exploit method for CVE-2016-3096 involves manipulating the create_script function to gain unauthorized access to write in a specific script location.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203