CVE-2015-1340: Linuxcontainers Lxd

High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

Affected products

Published 2019-04-22. Last modified 2026-06-17.