Branch: refs/heads/stable-1.1
Home: https://github.com/lxc/lxc
Commit: 61ecf69d7834921cc078e14d1b36c459ad8f91c7
https://github.com/lxc/lxc/commit/61ecf69d7834921cc078e14d1b36c459ad8f91c7
Author: Serge Hallyn <serge.hal...@ubuntu.com>
Date: 2015-07-22 (Wed, 22 Jul 2015)
Changed paths:
M src/lxc/lxclock.c
M src/tests/locktests.c
Log Message:
-----------
CVE-2015-1331: lxclock: use /run/lxc/lock rather than /run/lock/lxc
This prevents an unprivileged user to use LXC to create arbitrary file
on the filesystem.
Signed-off-by: Serge Hallyn <serge.hal...@ubuntu.com>
Signed-off-by: Tyler Hicks <tyhi...@canonical.com>
Acked-by: Stéphane Graber <stgra...@ubuntu.com>
Commit: 659e807c8dd1525a5c94bdecc47599079fad8407
https://github.com/lxc/lxc/commit/659e807c8dd1525a5c94bdecc47599079fad8407
Author: Stéphane Graber <stgra...@ubuntu.com>
Date: 2015-07-22 (Wed, 22 Jul 2015)
Changed paths:
M src/lxc/attach.c
Log Message:
-----------
CVE-2015-1334: Don't use the container's /proc during attach
A user could otherwise over-mount /proc and prevent the apparmor profile
or selinux label from being written which combined with a modified
/bin/sh or other commonly used binary would lead to unconfined code
execution.
Reported-by: Roman Fiedler
Signed-off-by: Stéphane Graber <stgra...@ubuntu.com>
Compare: https://github.com/lxc/lxc/compare/3d6347a4cd69...659e807c8dd1
_______________________________________________
lxc-devel mailing list
lxc-devel@lists.linuxcontainers.org
http://lists.linuxcontainers.org/listinfo/lxc-devel