Vulnerability Name: | CVE-2018-6556 (CCN-148027) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2018-08-07 | ||||||||||||||||||||||||||||||||||||
Published: | 2018-08-07 | ||||||||||||||||||||||||||||||||||||
Updated: | 2019-05-31 | ||||||||||||||||||||||||||||||||||||
Summary: | lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-417 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-6556 Source: SUSE Type: Mailing List, Third Party Advisory openSUSE-SU-2019:1227 Source: SUSE Type: Mailing List, Third Party Advisory openSUSE-SU-2019:1230 Source: SUSE Type: Mailing List, Third Party Advisory openSUSE-SU-2019:1275 Source: SUSE Type: UNKNOWN openSUSE-SU-2019:1481 Source: CCN Type: oss-sec Mailing List, Mon, 6 Aug 2018 12:27:03 -0400 CVE-2018-6556: lxc-user-nic allows for open() of arbitrary paths Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1783591 Source: CCN Type: Bugzilla Bug 988348 (CVE-2018-6556) AUDIT-0: CVE-2018-6556: lxc: enable setuid bit on lxc-user-nic Source: CONFIRM Type: Issue Tracking, Patch https://bugzilla.suse.com/show_bug.cgi?id=988348 Source: XF Type: UNKNOWN lxc-cve20186556-info-disc(148027) Source: CCN Type: lxc GIT Repository CVE 2018-6556: verify netns fd in lxc-user-nic Source: GENTOO Type: Third Party Advisory GLSA-201808-02 Source: UBUNTU Type: Third Party Advisory USN-3730-1 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |