CVE
CVE-2023-5536
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.
- Severity
- MEDIUM
- CVSS
- 5
- Published
- Modified
Linked Releases
| Distribution | Release | Status | Evidence |
|---|---|---|---|
| Ubuntu | 22.04.5 amd64 desktop | unknown | source |
| Ubuntu | 22.04.5 amd64 live-server | unknown | source |
| Ubuntu | 20.04.6 amd64 desktop | unknown | source |
| Ubuntu | 20.04.6 amd64 live-server | unknown | source |
| Ubuntu | 18.04.6 amd64 desktop | unknown | source |
| Ubuntu | 18.04.6 amd64 live-server | unknown | source |
| Ubuntu | 16.04.7 amd64 desktop | unknown | source |
| Ubuntu | 16.04.6 i386 desktop | unknown | source |
| Ubuntu | 16.04.7 amd64 server | unknown | source |
| Ubuntu | 16.04.6 i386 server | unknown | source |
| Ubuntu | 14.04.6 amd64 desktop | unknown | source |
| Ubuntu | 14.04.6 i386 desktop | unknown | source |
| Ubuntu | 14.04.6 amd64 server | unknown | source |
| Ubuntu | 14.04.6 i386 server | unknown | source |
References
- https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1829071
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5536
- https://discourse.ubuntu.com/t/easy-multi-user-lxd-setup/26215/4
- https://ubuntu.com/security/CVE-2023-5536
- https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1829071
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5536
- https://discourse.ubuntu.com/t/easy-multi-user-lxd-setup/26215/4
- https://ubuntu.com/security/CVE-2023-5536