CVE-2017-18641: Linuxcontainers Lxc
High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
Affected products
- Linuxcontainers Lxc: version 2.0.0 only
Published 2020-02-10. Last modified 2026-06-17.