Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16884

Опубликовано: 22 сент. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

Отчет

The AppArmor security module is not supported by Red Hat, on the other hand the flaw also affects SELinux based distributions like Red Hat Enterprise Linux.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8container-tools:1.0/runcOut of support scope
Red Hat OpenShift Container Platform 3.9runcOut of support scope
Red Hat Enterprise Linux 7 ExtrasruncFixedRHBA-2020:123201.04.2020
Red Hat Enterprise Linux 7 ExtrasdockerFixedRHSA-2020:123401.04.2020
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2019:426917.12.2019
Red Hat OpenShift Container Platform 4.1runcFixedRHSA-2019:394021.11.2019
Red Hat OpenShift Container Platform 4.2runcFixedRHSA-2019:407403.12.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-41
https://bugzilla.redhat.com/show_bug.cgi?id=1757214runc: AppArmor/SELinux bypass with malicious image that specifies a volume at /proc

EPSS

Процентиль: 53%
0.00301
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

CVSS3: 7.5
nvd
больше 5 лет назад

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

CVSS3: 7.5
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 5 лет назад

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other ...

suse-cvrf
больше 5 лет назад

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

EPSS

Процентиль: 53%
0.00301
Низкий

6.5 Medium

CVSS3