Serge Hallyn discovered that cgmanager did not consistently enforce proper nesting when modifying cgroup properties. A local attacker in a privileged container could use this to set cgroup values for all cgroups.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "cgmanager",
"binary_version": "0.24-0ubuntu7.1"
},
{
"binary_name": "cgmanager-tests",
"binary_version": "0.24-0ubuntu7.1"
},
{
"binary_name": "cgmanager-utils",
"binary_version": "0.24-0ubuntu7.1"
},
{
"binary_name": "libcgmanager-dev",
"binary_version": "0.24-0ubuntu7.1"
},
{
"binary_name": "libcgmanager0",
"binary_version": "0.24-0ubuntu7.1"
}
]
}