CVE-2018-6556 Details
Description
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-417 | Communication Channel Errors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| canonical ubuntu linux | 18.04 |
CPE
Remediation
| |
| linuxcontainers lxc | >= 2.0.0, <= 2.0.9 >= 3.0.0, < 3.0.2 |
CPE
Remediation
| |
| suse caas platform | 1.0 2.0 |
CPE
Remediation
| |
| suse openstack cloud | 6 |
CPE
Remediation
| |
| suse suse linux enterprise server | 11 sp3 11 sp4 |
CPE
Remediation
| |
| opensuse leap | 15.0 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 31, 2019 | CVE Modified | [email protected] |
| Apr 27, 2019 | Modified Analysis | [email protected] |
| Apr 25, 2019 | CVE Modified | [email protected] |
| Apr 18, 2019 | CVE Modified | [email protected] |
| Apr 17, 2019 | CVE Modified | [email protected] |
| Oct 21, 2018 | CVE Modified | [email protected] |
| Oct 12, 2018 | Initial Analysis | [email protected] |