LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "golang-github-lxc-lxd-dev" }, { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "lxc2" }, { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "lxd" }, { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "lxd-client" }, { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "lxd-client-dbgsym" }, { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "lxd-dbgsym" }, { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "lxd-tools" }, { "binary_version": "2.0.2-0ubuntu1~16.04.1", "binary_name": "lxd-tools-dbgsym" } ] }