Matthias Gerstner discovered that LXC incorrectly handled the lxc-user-nic utility. A local attacker could possibly use this issue to open arbitrary files.
{ "binaries": [ { "binary_name": "liblxc-common", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "liblxc-common-dbgsym", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "liblxc-dev", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "liblxc1", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "liblxc1-dbgsym", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "libpam-cgfs", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "libpam-cgfs-dbgsym", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "lxc", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "lxc-dev", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "lxc-utils", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "lxc-utils-dbgsym", "binary_version": "3.0.1-0ubuntu1~18.04.2" }, { "binary_name": "lxc1", "binary_version": "3.0.1-0ubuntu1~18.04.2" } ], "availability": "No subscription required" }