Description
The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2813-1
Patch x_refsource_confirm
https://github.com/lxc/lxcfs/commit/8ee2a503e102b1a43ec4d83113dc275ab20a869a
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1512854
Scores
EPSS
0.0004
EPSS Percentile
10.8%
Details
CWE
CWE-264
Status
published
Products (3)
canonical/lxcfs
< 0.11
canonical/ubuntu_linux
15.04
canonical/ubuntu_linux
15.10
Published
Dec 07, 2015
Tracked Since
Feb 18, 2026