<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2023-0153</id>
    <title>An update for lxc is now available for HCE 2.0</title>
    <severity>Low</severity>
    <release>HCE 2.0</release>
    <issued date="2023-03-27 08:19:42"/>
    <updated date="2023-03-27 08:19:42"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2022-47952" id="CVE-2022-47952" title="CVE-2022-47952 Base Score: 3.3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" type="cve"/>
    </references>
    <description>Security Fix(es):

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because &quot;Failed to open&quot; often indicates that a file does not exist, whereas &quot;does not refer to a network namespace path&quot; often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that &quot;we will report back to the user that the open() failed but the user has no way of knowing why it failed&quot;; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist. (CVE-2022-47952)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="lxc">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="lxc" version="4.0.3" release="2022031701.r15.hce2">
          <filename>lxc-4.0.3-2022031701.r15.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="lxc-devel" version="4.0.3" release="2022031701.r15.hce2">
          <filename>lxc-devel-4.0.3-2022031701.r15.hce2.aarch64.rpm</filename>
        </package>
        <package arch="noarch" name="lxc-help" version="4.0.3" release="2022031701.r15.hce2">
          <filename>lxc-help-4.0.3-2022031701.r15.hce2.noarch.rpm</filename>
        </package>
        <package arch="aarch64" name="lxc-libs" version="4.0.3" release="2022031701.r15.hce2">
          <filename>lxc-libs-4.0.3-2022031701.r15.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="lxc" version="4.0.3" release="2022031701.r15.hce2">
          <filename>lxc-4.0.3-2022031701.r15.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="lxc-devel" version="4.0.3" release="2022031701.r15.hce2">
          <filename>lxc-devel-4.0.3-2022031701.r15.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="lxc-libs" version="4.0.3" release="2022031701.r15.hce2">
          <filename>lxc-libs-4.0.3-2022031701.r15.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
