LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/lxc/lxd(Go) | 0 | 0.0.0-20151004155856-19c6961cc101 | N/A |
CVSS Metrics