lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1335
Reference (s):
- BID:76894
- URL: http://www.securityfocus.com/bid/76894
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1476662
- https://github.com/lxc/lxc/commit/592fd47a6245508b79fe6ac819fe6d3b2c1289be

