lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://lists.linuxcontainers.org/pipermail/lxc-devel/2017-March/015535.html | vendor advisory mailing list |
https://github.com/lxc/lxc/commit/16af238036a5464ae8f2420ed3af214f0de875f9 | patch issue tracking |
http://www.securityfocus.com/bid/96777 | third party advisory vdb entry |
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1654676 | third party advisory |
http://www.ubuntu.com/usn/USN-3224-1 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2017/03/09/4 | third party advisory mailing list |
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.html | vendor advisory |