← Vulnerability feed

Vulnerability record · CVE-2016-8649 · published 1 May 2017

CVE-2016-8649: Linuxcontainers lxc permissions and access controls vulnerability

Linuxcontainers · Lxc

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

9.1 CVSS 3.0 Critical EPSS 2.8% · top 14.0% CWE-264 · Permissions and access controls
9.1CVSS 3.0 base score, v2 9.0
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8649 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2019-5736runc container escape via /proc/self/exe overwrite of host binaryrunc through 1.0-rc6, as used in Docker before 18.09.2 and other products, mishandles file descriptors related to /proc/self/exe, letting an attacker…EPSS 98%analysed8.6CVE-2016-10124Linuxcontainers lxc improper access control vulnerabilityAn issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the p…EPSS 1.5%8.1CVE-2017-18641Linuxcontainers lxc improper authentication vulnerabilityIn LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.EPSS 1.4%7.2CVE-2015-1335Linuxcontainers lxc link following vulnerabilitylxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (…EPSS 0.46%7.2CVE-2013-6441Linuxcontainers lxc permissions and access controls vulnerabilityThe lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local user…EPSS 0.50%4.9CVE-2015-1331Linuxcontainers lxc link following vulnerabilitylxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.EPSS 0.46%4.6CVE-2015-1334Linuxcontainers lxc vulnerabilityattach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confineme…EPSS 0.37%4.3CVE-2026-39402Linuxcontainers lxc incorrect authorization vulnerabilitylxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an…EPSS 0.14%

Source: NIST National Vulnerability Database (record CVE-2016-8649), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.