VYPR

LXD

by Ubuntu

CVEs (3)

  • CVE-2023-49721MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

  • CVE-2015-1340HigApr 22, 2019
    risk 0.39cvss 7.0epss 0.01

    LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

  • CVE-2023-5536MedDec 12, 2023
    risk 0.33cvss 5.0epss 0.00

    A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.