← Back

Linuxcontainers

linuxcontainers

32 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Incus
incus
Lxc
lxc
Cgmanager
cgmanager
Lxd
lxd

CVEs (32)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linuxcontainers
1Lxc
Nov 21, 2024
Feb 10, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
1Linuxcontainers
1Lxd
Nov 21, 2024
Apr 22, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system...Show more
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.Show less
13Apache
CanonicalD2iq+10 more
19Backports Sle
Container Development KitDc/os+16 more
Jun 17, 2026
Feb 11, 2019
N/A· v4
8.6 HIGH· v3
9.3 HIGH· v2
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as r...Show more
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.Show less
4Canonical
LinuxcontainersOpensuse+1 more
6Caas Platform
LeapLxc+3 more
Jun 17, 2026
Aug 10, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise...Show more
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.Show less
1Linuxcontainers
1Lxc
May 13, 2026
May 1, 2017
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the ope...Show more
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.Show less
1Linuxcontainers
1Lxc
May 13, 2026
Mar 14, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
1Linuxcontainers
1Lxc
May 6, 2026
Jan 9, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the te...Show more
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.Show less
2Canonical
Linuxcontainers
2Lxc
Ubuntu Linux
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
1Linuxcontainers
1Lxc
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or...Show more
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.Show less
1Linuxcontainers
1Lxc
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
2Canonical
Linuxcontainers
2Cgmanager
Ubuntu Linux
May 6, 2026
Jan 7, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
1Linuxcontainers
1Lxc
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.