LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1342
Reference (s):
- https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1508481
- https://github.com/lxc/lxcfs/commit/a8b6c3e0537e90fba3c55910fd1b7229d54a60a7
- UBUNTU:USN-2813-1
- URL: http://www.ubuntu.com/usn/USN-2813-1