USN-3136-1: LXC vulnerability
USN-3136-1: LXC vulnerability Ubuntu Security Notice USN-3136-1 23rd November, 2016 lxc vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary LXC could be made to allow containers to access to the host filesystem. Software description lxc – Linux Containers userspace tools Details Roman Fiedler discovered a directory traversal flaw in lxc-attach. Anattacker with access to an LXC container could exploit this flaw to accessfiles outside of the container. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.10: lxc1 2.0.5-0ubuntu1.2 liblxc1 2.0.5-0ubuntu1.2 Ubuntu 16.04 LTS: lxc1 2.0.5-0ubuntu1~ubuntu16.04.3 liblxc1 2.0.5-0ubuntu1~ubuntu16.04.3 Ubuntu 14.04 LTS: lxc 1.0.8-0ubuntu0.4 liblxc1 1.0.8-0ubuntu0.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-8649 Source: [ more… ]