LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 15.04 (including) | 15.04 (including) |
Ubuntu_linux | Canonical | 15.10 (including) | 15.10 (including) |
Lxcfs | Ubuntu | devel | * |
Lxcfs | Ubuntu | vivid | * |
Lxcfs | Ubuntu | wily | * |