Bug 1263126 - (CVE-2015-6927) CVE-2015-6927 vzctl: gaining control over simfs containers
CVE-2015-6927 vzctl: gaining control over simfs containers
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 1263127
  Show dependency treegraph
Reported: 2015-09-15 03:46 EDT by Martin Prpič
Modified: 2016-07-07 05:02 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Martin Prpič 2015-09-15 03:46:05 EDT
Debian fixed the following issue in vzctl:

It was discovered that vzctl, a set of control tools for the OpenVZ server virtualisation solution, determined the storage layout of containers based on the presense of an XML file inside the container. An attacker with local root privileges in a simfs-based container could gain control over ploop-based containers. Further information on the prerequites of such an attack can be found at:


Debian advisory:

Comment 1 Martin Prpič 2015-09-15 03:46:28 EDT
Created vzctl tracking bugs for this issue:

Affects: fedora-all [bug 1263127]
Comment 2 Salvatore Bonaccorso 2015-09-15 15:00:44 EDT
FYI, a CVE was requested directly to MITRE CVE assignment team for this. It was assigned CVE-2015-6927.


Note You need to log in before you can comment on or make changes to this bug.