It was discovered that local users could use the criu daemon to create arbitrary files and take ownership of existing files, due to the creation of log and dump files in a user-supplied directory path. This allows unprivileged local users to gain root privileges. Acknowledgements: This issue was discovered by Florian Weimer of Red Hat Product Security.
Created criu tracking bugs for this issue: Affects: fedora-all [bug 1256747]
Upstream discussion: http://lists.openvz.org/pipermail/criu/2015-August/021847.html