SB2018082310 - Information disclosure in LXC
Published: August 23, 2018
Security Bulletin ID
SB2018082310
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2018-6556)
The vulnerability allows a local unauthenticated attacker to obtain potentially sensitive information on the target system.The weakness exists due to lxc-user-nic unconditionally opens a user provided path when asked to delete a network interface. A local attacker can check for the existence of a path which he wouldn't otherwise be able to reach and trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys).
Remediation
Install update from vendor's website.