The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
2015-12-07T20:59:01.647
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | canonical | ubuntu_linux | 15.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.10 | Yes |
Application | canonical | lxcfs | ≤ 0.11 | Yes |