CVE-2015-3627

Source
https://cve.org/CVERecord?id=CVE-2015-3627
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2015-3627.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2015-3627
Aliases
Downstream
Related
Withdrawn
2026-01-27T04:15:00Z
Published
2015-05-18T15:59:14Z
Modified
2026-07-17T21:00:15Z
Summary
[none]
Details

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

References

Affected packages