LOW🇵🇱 Wersja polska

CVE-2018-6556

CVSS 3.3v3.0pub. 2018-08-10upd. 2024-11-21

lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • Canonical Ubuntu

    OS
    Canonical
    18.04
  • Linuxcontainers Lxc

    APP
    Linuxcontainers
    2.0.0 – 2.0.93.0.0 – 3.0.2 (excl.)
  • Opensuse Leap

    OS
    Opensuse
    15.0
  • SUSE Caas Platform

    APP
    Suse
    1.02.0
  • SUSE Openstack Cloud

    APP
    Suse
    6
  • SUSE Linux Enterprise Server

    OS
    Suse
    11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2022-0543CRITICAL10.0⚠ KEVPL ✓same product

Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)

CVE-2020-16846CRITICAL9.8⚠ KEVPL ✓same product

SaltStack Salt API — shell injection przez klienta SSH (RCE)

CVE-2020-12641CRITICAL9.8⚠ KEVPL ✓same product

Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick

CVE-2020-11651CRITICAL9.8⚠ KEVPL ✓same product

SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE