CVE-2019-16884

Aliases:GHSA-fgv8-vj5c-2ppqGO-2021-0085
Modified
Published: 25 Sept 2019, 00:00
Last modified:05 Aug 2024, 01:24

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.32% LOW
0% probability -0.24%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

25 Sept 2019, 00:00
Published
Vulnerability first disclosed
05 Aug 2024, 01:24
Last Modified
Vulnerability information updated

Description

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 0.32% Percentile: 55%

Techniques & Countermeasures

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Affected Systems

  • canonicalubuntu_linux

    18.04 | 19.10

  • dockerdocker

    ≤ 19.03.2

  • fedoraprojectfedora

    29 | 30 | 31

  • github.com/opencontainersrunc

    < 1.0.0-rc8.0.20190930145003-cad42f6e0932

  • github.com/opencontainersselinux

    < 1.3.1-0.20190929122143-5215b1806f52

  • linuxfoundationrunc

    ≥ 0.0.1, ≤ 0.1.1 | 1.0.0:rc1 | 1.0.0:rc2 | 1.0.0:rc3 | 1.0.0:rc4 | 1.0.0:rc5 | 1.0.0:rc6 | 1.0.0:rc7 | 1.0.0:rc8

  • opensuseleap

    15.0 | 15.1

  • redhatenterprise_linux

    8.0

  • redhatenterprise_linux_eus

    8.1 | 8.2 | 8.4

  • redhatenterprise_linux_server_aus

    8.2 | 8.4

  • redhatenterprise_linux_server_tus

    8.2 | 8.4

  • redhatopenshift_container_platform

    4.1 | 4.2

References (28)