First published: Tue Dec 12 2023(Updated: )
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | <24.04 |
Remove users from lxd group and configure multi-user LXD mode. https://discourse.ubuntu.com/t/easy-multi-user-lxd-setup/26215/4
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5536 has been classified as a high-severity vulnerability due to the potential for privilege escalation.
To mitigate CVE-2023-5536, ensure that users in the lxd group do not have unnecessary privileges and apply the latest security updates from Ubuntu.
CVE-2023-5536 affects Ubuntu Server versions prior to 24.04 with the default LXD configuration.
CVE-2023-5536 is a privilege escalation vulnerability that allows unauthorized access to root privileges.
CVE-2023-5536 typically requires local access to the system, as it involves privileged users in the lxd group.