CVE-2017-5985: Low severity linuxcontainers Lxc vulnerability
Published Mar 14, 2017
·Updated
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
Affected Software
2 affected components
linuxcontainers Lxc<=1.0.9
linuxcontainers Lxc>=2.0.0<=2.0.6
Remediation
Event History
Mar 14, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5985?
CVE-2017-5985 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2017-5985?
To fix CVE-2017-5985, update LXC to version 1.0.10 or later, or to any version in the 2.0.x series and above.
3
Who is affected by CVE-2017-5985?
Local users with lxc-usernet allocations in LXC versions up to 1.0.9 and between 2.0.0 and 2.0.6 are affected by CVE-2017-5985.
4
What types of attacks can exploit CVE-2017-5985?
CVE-2017-5985 can be exploited by local users to create unauthorized network interfaces on the host.
5
Does CVE-2017-5985 affect newer versions of LXC?
No, CVE-2017-5985 does not affect LXC versions later than 2.0.6.