CVE-2018-6556: The lxc-user-nic component of LXC allows unprivileged users to open arbitrary files
Last updated 25 August 2025
Other sources
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-6556?
CVE-2018-6556 is a vulnerability in lxc-user-nic where an unprivileged user can open a user provided path, potentially allowing them to check for the existence of a path they wouldn't otherwise be able to reach or trigger side effects.
What is the severity of CVE-2018-6556?
The severity of CVE-2018-6556 is low with a CVSS score of 3.3.
What software is affected by CVE-2018-6556?
The affected software includes lxc versions 3.0.1-0ubuntu1~18.04.2, 1:3.1.0+really3.0.3-8, 1:3.1.0+really3.0.3-8+deb10u1, 1:4.0.6-2+deb11u2, 1:5.0.2-1+deb12u1, and 1:5.0.3-1.
How do I fix CVE-2018-6556?
To fix CVE-2018-6556, update lxc to version 3.0.1-0ubuntu1~18.04.2 or apply the available patches depending on your distribution.
Where can I find more information about CVE-2018-6556?
You can find more information about CVE-2018-6556 at the following references: [link1], [link2], [link3].