Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16884

Опубликовано: 22 сент. 2019
Источник: redhat
CVSS3: 6.5

Описание

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

Отчет

The AppArmor security module is not supported by Red Hat, on the other hand the flaw also affects SELinux based distributions like Red Hat Enterprise Linux.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8container-tools:1.0/runcOut of support scope
Red Hat OpenShift Container Platform 3.9runcOut of support scope
Red Hat Enterprise Linux 7 ExtrasruncFixedRHBA-2020:123201.04.2020
Red Hat Enterprise Linux 7 ExtrasdockerFixedRHSA-2020:123401.04.2020
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2019:426917.12.2019
Red Hat OpenShift Container Platform 4.1runcFixedRHSA-2019:394021.11.2019
Red Hat OpenShift Container Platform 4.2runcFixedRHSA-2019:407403.12.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-41
https://bugzilla.redhat.com/show_bug.cgi?id=1757214runc: AppArmor/SELinux bypass with malicious image that specifies a volume at /proc

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

CVSS3: 7.5
nvd
почти 6 лет назад

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 6 лет назад

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other ...

suse-cvrf
больше 5 лет назад

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

6.5 Medium

CVSS3