CVE Published: 01/05/2017 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: redhat |
Vendor: n/a |
Product: LXC before 1.0.9 and 2.x before 2.0.6 Status : PUBLISHED
CVE-2016-8649 Description
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host\'s /proc, to access the rest of the host\'s filesystem via the openat() family of syscalls.