CVE-2018-6556
3.3
LOW
CVSS 3.1
EPSS 0.07%
Description
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
How to fix CVE-2018-6556
To remediate CVE-2018-6556, upgrade the affected package to a fixed version below.
- —upgrade to 2.1.1-r9 or later
- —upgrade to 1:2.0.9-6.1 or later
Is CVE-2018-6556 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.1.1-r9
- from 0, < 1:2.0.9-6.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.3 | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |