{"id":"GO-2021-0071","summary":"Race condition in github.com/lxc/lxd","details":"A race between chown and chmod operations during a container filesystem shift may allow a user who can modify the filesystem to chmod an arbitrary path of their choice, rather than the expected path.","aliases":["CVE-2015-1340","GHSA-8mpq-fmr3-6jxv"],"modified":"2024-06-03T20:51:31Z","published":"2021-04-14T20:04:52Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2021-0071"},"references":[{"type":"FIX","url":"https://github.com/lxc/lxd/commit/19c6961cc1012c8a529f20807328a9357f5034f4"},{"type":"WEB","url":"https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1502270"}],"affected":[{"package":{"name":"github.com/lxc/lxd","ecosystem":"Go","purl":"pkg:golang/github.com/lxc/lxd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20151004155856-19c6961cc101"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/lxc/lxd/shared","symbols":["IdmapSet.doUidshiftIntoContainer"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2021-0071.json"}}],"schema_version":"1.7.3","credits":[{"name":"Seth Arnold"}]}