CVE-2022-47952 Unknown

CVE-2022-47952

SUSE Released: January 03, 2023 Updated: February 16, 2025 Restart Required

Description

CVE-2022-47952 lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist. The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).

Fixed Vulnerabilities 1

CVE-2018-6556 N/A 0.0 ⚠️ KEV fixed
Aug 10, 2018

lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user…

Quick Info

Patch ID: CVE-2022-47952
Vendor: SUSE
Severity: Unknown
CVEs Fixed: 1
Restart: Required

Vendor

SUSE

Additional Info

advisory id: CVE-2022-47952
advisory type: Security Update
cvrf filename: cvrf-CVE-2022-47952.xml

Share