Vulnerabilities > Linuxcontainers > LXC > 4.0.2

DATE CVE VULNERABILITY TITLE RISK
2023-01-01 CVE-2022-47952 Information Exposure Through Discrepancy vulnerability in Linuxcontainers LXC
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists.
local
low complexity
linuxcontainers CWE-203
3.3