The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6441