CVE-2014-3519: Openvz Vzkernel
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow local container users with CAP_DAC_READ_SEARCH capability to bypass an intended container protection mechanism and access arbitrary files on a filesystem via vectors related to use of the file_handle structure.
Affected products
- Openvz Vzkernel: version 2.6.32 only
Published 2018-02-01. Last modified 2026-06-17.