CVE-2015-3627

Libcontainer <1.6.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

References (4)

Core 4

Scores

EPSS 0.0061
EPSS Percentile 44.4%

Details

CWE
CWE-59
Status published
Products (3)
docker/docker < 1.6
docker/docker 0 - 1.6.1Go
docker/libcontainer < 1.6.0
Published May 18, 2015
Tracked Since Feb 18, 2026