Wrong mode on unix.socket when socket activated
Bug #1515689 reported by
Stéphane Graber
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
lxd (Ubuntu) |
Fix Released
|
Critical
|
Stéphane Graber | ||
Trusty |
Fix Released
|
Critical
|
Stéphane Graber | ||
Wily |
Fix Released
|
Critical
|
Marc Deslauriers | ||
Xenial |
Fix Released
|
Critical
|
Stéphane Graber |
Bug Description
LXD uses systemd socket activation to start the daemon except at installation time where the daemon is started directly.
Systemd defaults to 0666 for its unix sockets instead of respecting umask, leading to /var/lib/
The fix is simply to specify a mode of 0660 in the systemd unit.
This affects LXD in wily, xenial and trusty-backports. vivid's version is unaffected as we didn't have socket activation back then.
CVE References
Changed in lxd (Ubuntu Xenial): | |
status: | Triaged → Fix Committed |
Changed in lxd (Ubuntu Trusty): | |
status: | New → Fix Committed |
importance: | Undecided → Critical |
assignee: | nobody → Stéphane Graber (stgraber) |
Changed in lxd (Ubuntu Xenial): | |
assignee: | nobody → Stéphane Graber (stgraber) |
Changed in lxd (Ubuntu Wily): | |
status: | New → Triaged |
importance: | Undecided → Critical |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in lxd (Ubuntu Trusty): | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
Upstream bug report: https:/ /github. com/lxc/ lxd/issues/ 1307