Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0376-1

Опубликовано: 07 фев. 2020
Источник: suse-cvrf

Описание

Security update for docker-runc

This update for docker-runc fixes the following issues:

  • CVE-2019-19921: Fixed a volume mount race condition with shared mounts (bsc#1160452).

Список пакетов

SUSE Linux Enterprise Module for Containers 12
docker-runc-1.0.0rc8+gitr3917_3e425f80a8c9-1.40.1

Описание

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)


Затронутые продукты
SUSE Linux Enterprise Module for Containers 12:docker-runc-1.0.0rc8+gitr3917_3e425f80a8c9-1.40.1

Ссылки