Jann Horn discovered that LXC incorrectly verified permissions when creating virtual network interfaces. A local attacker could possibly use this issue to create virtual network interfaces in network namespaces that they do not own.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "liblxc1",
"binary_version": "1.0.9-0ubuntu3"
},
{
"binary_name": "lxc",
"binary_version": "1.0.9-0ubuntu3"
},
{
"binary_name": "lxc-dev",
"binary_version": "1.0.9-0ubuntu3"
},
{
"binary_name": "lxc-templates",
"binary_version": "1.0.9-0ubuntu3"
},
{
"binary_name": "lxc-tests",
"binary_version": "1.0.9-0ubuntu3"
},
{
"binary_name": "python3-lxc",
"binary_version": "1.0.9-0ubuntu3"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "liblxc1",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "lua-lxc",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "lxc",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "lxc-common",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "lxc-dev",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "lxc-templates",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "lxc-tests",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "lxc1",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
},
{
"binary_name": "python3-lxc",
"binary_version": "2.0.7-0ubuntu1~16.04.2"
}
]
}