CVE-2019-19921

Aliases:GHSA-fh74-hm69-rqjwGO-2021-0087
Modified
Published: 12 Feb 2020, 00:00
Last modified:05 Aug 2024, 02:32

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
7 HIGH
v3.1 (nvd)
EPSS Score
0.19% LOW
0% probability +0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Feb 2020, 00:00
Published
Vulnerability first disclosed
05 Aug 2024, 02:32
Last Modified
Vulnerability information updated

Description

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

CVSS Metrics

  • v3.1HIGHScore: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:U
  • v2.0MEDIUMScore: 4.4AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.19% Percentile: 41%

Techniques & Countermeasures

  • CWE-706Use of Incorrectly-Resolved Name or Reference

    The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Affected Systems

  • canonicalubuntu_linux

    18.04 | 19.10

  • debiandebian_linux

    9.0 | 10.0

  • github.com/opencontainersrunc

    < 1.0.0-rc9.0.20200122160610-2fc03cc11c77

  • linuxfoundationrunc

    ≤ 0.1.1 | 1.0.0:rc1 | 1.0.0:rc2 | 1.0.0:rc3 | 1.0.0:rc4 | 1.0.0:rc5 | 1.0.0:rc6 | 1.0.0:rc7 | 1.0.0:rc8 | 1.0.0:rc9

  • opensuseleap

    15.1

  • redhatopenshift_container_platform

    4.1 | 4.2

References (26)