lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1331
Reference (s):
- BID:75999
- URL: http://www.securityfocus.com/bid/75999
- https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1470842
- https://github.com/lxc/lxc/commit/72cf81f6a3404e35028567db2c99a90406e9c6e6
- DEBIAN:DSA-3317

