Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Ubuntu 16.04 LXD Access Issues: USN-2988-1 Moderate Security Advisory

Ubuntu Large Esm H500
Several security issues were fixed in LXD.
=========================================================================Ubuntu Security Notice USN-2988-1
May 31, 2016

lxd vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10

Summary:

Several security issues were fixed in LXD.

Software Description:
- lxd: Container hypervisor based on LXC

Details:

Robie Basak discovered that LXD incorrectly set permissions when setting up
a loop based ZFS pool. A local attacker could use this issue to copy and
read the data of any LXD container. (CVE-2016-1581)

Robie Basak discovered that LXD incorrectly set permissions when switching
an unprivileged container into privileged mode. A local attacker could use
this issue to access any world readable path in the container directory,
including setuid binaries. (CVE-2016-1582)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  lxd                             2.0.2-0ubuntu1~16.04.1

Ubuntu 15.10:
  lxd                             0.20-0ubuntu4.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2988-1
  CVE-2016-1581, CVE-2016-1582

Package Information:
  https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1
  https://launchpad.net/ubuntu/+source/lxd/0.20-0ubuntu4.2


Ubuntu 16.04 LXD Access Issues: USN-2988-1 Moderate Security Advisory

ubuntu
Calendar Grey May 31, 2016
Dist Ubuntu Esm H88
Multiple vulnerabilities addressed in LXD. Review Ubuntu patches to safeguard your systems immediately.
Several security issues were fixed in LXD.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: lxd 2.0.2-0ubuntu1~16.04.1 Ubuntu 15.10: lxd 0.20-0ubuntu4.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2988-1

CVE-2016-1581, CVE-2016-1582

May 31, 2016

Package Information

https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1 https://launchpad.net/ubuntu/+source/lxd/0.20-0ubuntu4.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here