First published: Tue Mar 14 2017(Updated: )
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxcontainers Lxc | <=1.0.9 | |
Linuxcontainers Lxc | >=2.0.0<=2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5985 has been rated as a medium severity vulnerability.
To fix CVE-2017-5985, update LXC to version 1.0.10 or later, or to any version in the 2.0.x series and above.
Local users with lxc-usernet allocations in LXC versions up to 1.0.9 and between 2.0.0 and 2.0.6 are affected by CVE-2017-5985.
CVE-2017-5985 can be exploited by local users to create unauthorized network interfaces on the host.
No, CVE-2017-5985 does not affect LXC versions later than 2.0.6.