Home/Product/linuxcontainers lxc
Product

linuxcontainers lxc

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-39402
< 7.0.0
lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() func
6.5MEDIUM
CVE-2022-47952
<= 5.0.1
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even withi
3.3LOW
CVE-2017-18641
all versions
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to boot
8.1HIGH
CVE-2019-5736
< 3.2.0
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and
8.6HIGH
CVE-2018-6556
>= 2.0.0 and <= 2.0.9
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used b
3.3LOW
CVE-2016-8649
< 1.0.9
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited fil
9.1CRITICAL
CVE-2017-5985
<= 1.0.9
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host a
3.3LOW
CVE-2016-10124
<= 2.0.0
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session
8.6HIGH
CVE-2015-1335
<= 1.0.7
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a sy
CVE-2015-1334
<= 1.1.2
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor o
CVE-2015-1331
<= 1.1.2
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
CVE-2013-6441
<= 0.9.0
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, whic
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin