LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://linuxcontainers.org/lxd/news/ | vendor advisory |
http://www.ubuntu.com/usn/USN-2988-1 | vendor advisory |