Upstream information
Description
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.SUSE information
Overall state of this security issue: Running
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 9.3 |
Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Complete |
Integrity Impact | Complete |
Availability Impact | Complete |
National Vulnerability Database | SUSE | |
---|---|---|
Base Score | 8.6 | 7.5 |
Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
Access Vector | Local | Local |
Access Complexity | Low | High |
Privileges Required | None | Low |
User Interaction | Required | Required |
Scope | Changed | Changed |
Confidentiality Impact | High | High |
Integrity Impact | High | High |
Availability Impact | High | High |
CVSSv3 Version | 3.1 | 3 |
- SUSE-SU-2019:0337-1, published Tue Feb 12 13:08:36 MST 2019
- SUSE-SU-2019:0362-1, published Wed Feb 13 10:10:45 MST 2019
- SUSE-SU-2019:0385-1, published Wed Feb 13 13:10:44 MST 2019
- SUSE-SU-2019:0495-1, published Tue Feb 26 13:10:41 MST 2019
- SUSE-SU-2019:0573-1, published Fri Mar 8 10:09:22 MST 2019
- SUSE-SU-2019:1234-1, published Tue May 14 16:39:01 MDT 2019
- SUSE-SU-2019:1234-2, published Thu Jun 13 13:11:46 MDT 2019
- SUSE-SU-2019:2117-1, published Tue Aug 13 10:10:27 MDT 2019
- SUSE-SU-2019:2119-1, published Tue Aug 13 10:13:15 MDT 2019
- TID000019404, published Mon Mar 9 15:51:05 CET 2020
- TID7023708, published Tue Feb 12 18:55:47 CET 2019
- openSUSE-SU-2019:0170-1, published Wed, 13 Feb 2019 21:09:10 +0100 (CET)
- openSUSE-SU-2019:0201-1, published Mon, 18 Feb 2019 21:26:39 +0100 (CET)
- openSUSE-SU-2019:0208-1, published Tue, 19 Feb 2019 15:14:14 +0100 (CET)
- openSUSE-SU-2019:0252-1, published Wed, 27 Feb 2019 12:17:02 +0100 (CET)
- openSUSE-SU-2019:0295-1, published Wed, 6 Mar 2019 21:10:52 +0100 (CET)
- openSUSE-SU-2019:1079-1, published Sat, 30 Mar 2019 00:20:25 +0100 (CET)
- openSUSE-SU-2019:1227-1, published Wed, 17 Apr 2019 21:25:59 +0200 (CEST)
- openSUSE-SU-2019:1275-1, published Thu, 25 Apr 2019 21:09:01 +0200 (CEST)
- openSUSE-SU-2019:1444-1, published Mon, 27 May 2019 12:11:28 +0200 (CEST)
- openSUSE-SU-2019:1481-1, published Fri, 31 May 2019 21:11:48 +0200 (CEST)
- openSUSE-SU-2019:1499-1, published Mon, 3 Jun 2019 15:12:25 +0200 (CEST)
- openSUSE-SU-2019:1506-1, published Mon, 3 Jun 2019 18:11:12 +0200 (CEST)
- openSUSE-SU-2019:2021-1, published Fri, 30 Aug 2019 00:13:28 +0200 (CEST)
- openSUSE-SU-2019:2245-1, published Thu, 3 Oct 2019 18:20:43 +0200 (CEST)
- openSUSE-SU-2019:2286-1, published Mon, 7 Oct 2019 21:18:10 +0200 (CEST)
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
Image SLES15-EC2-CHOST-HVM-BYOS |
| |
Image SLES15-SP1-CHOST-BYOS-Ali Image SLES15-SP1-CHOST-BYOS-Azure Image SLES15-SP1-CHOST-BYOS-EC2 Image SLES15-SP1-CHOST-BYOS-GCE Image SLES15-SP1-CHOST-BYOS-OpenStack Image SLES15-SP2-CHOST-BYOS-Ali Image SLES15-SP2-CHOST-BYOS-Azure Image SLES15-SP2-CHOST-BYOS-EC2 Image SLES15-SP2-CHOST-BYOS-GCE Image SLES15-SP2-CHOST-BYOS-OpenStack |
| |
Openstack Cloud Magnum Orchestration 7 |
| Patchnames: SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2019-385 |
SUSE CaaS Platform 3.0 |
| Patchnames: SUSE-CAASP-3.0-2019-2119 SUSE-CAASP-3.0-2019-337 |
SUSE Linux Enterprise High Performance Computing 12 SP5 SUSE Linux Enterprise Server 12 SP5 |
| |
SUSE Linux Enterprise Module for Containers 12 |
| Patchnames: SUSE-SLE-Module-Containers-12-2019-2119 SUSE-SLE-Module-Containers-12-2019-385 SUSE-SLE-Module-Containers-12-2019-573 |
SUSE Linux Enterprise Module for Containers 15 SP1 |
| Patchnames: SUSE-SLE-Module-Containers-15-SP1-2019-1234 SUSE-SLE-Module-Containers-15-SP1-2019-2117 |
SUSE Linux Enterprise Module for Containers 15 SP2 |
| |
SUSE Linux Enterprise Module for Containers 15 |
| Patchnames: SUSE-SLE-Module-Containers-15-2019-1234 SUSE-SLE-Module-Containers-15-2019-2117 SUSE-SLE-Module-Containers-15-2019-362 SUSE-SLE-Module-Containers-15-2019-495 |
SUSE Linux Enterprise Module for Desktop Applications 15 SP1 |
| |
SUSE Linux Enterprise Module for Desktop Applications 15 SP2 |
| |
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 |
| Patchnames: SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-1234 SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-2117 |
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 |
| Patchnames: SUSE-SLE-Module-Development-Tools-OBS-15-2019-1234 SUSE-SLE-Module-Development-Tools-OBS-15-2019-2117 SUSE-SLE-Module-Development-Tools-OBS-15-2019-362 SUSE-SLE-Module-Development-Tools-OBS-15-2019-495 |
SUSE OpenStack Cloud 6-LTSS |
| Patchnames: SUSE-OpenStack-Cloud-6-LTSS-2019-2119 SUSE-OpenStack-Cloud-6-LTSS-2019-385 SUSE-OpenStack-Cloud-6-LTSS-2019-573 |
openSUSE Leap 15.0 |
| Patchnames: openSUSE-2019-1275 openSUSE-2019-1499 openSUSE-2019-2021 openSUSE-2019-208 openSUSE-2019-252 openSUSE-2019-295 |
openSUSE Leap 15.1 |
| Patchnames: openSUSE-2019-1444 openSUSE-2019-2021 openSUSE-2019-2245 |
openSUSE Leap 42.3 |
| Patchnames: openSUSE-2019-1079 openSUSE-2019-1481 openSUSE-2019-201 |
Status of this issue by product and package
Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification.
Product(s) | Source package | State |
---|---|---|
Magnum Orchestration | docker-runc | In progress |
Magnum Orchestration | runc | In progress |
SUSE CaaS Platform 3.0 | docker-runc | Released |
SUSE CaaS Platform 3.0 | runc | Released |
SUSE Container as a Service Platform 1.0 | runc | Affected |
SUSE Container as a Service Platform 2.0 | runc | Affected |
SUSE Linux Enterprise 12 Module for Containers | containerd | Released |
SUSE Linux Enterprise 12 Module for Containers | docker | Released |
SUSE Linux Enterprise 12 Module for Containers | docker-runc | Released |
SUSE Linux Enterprise 12 Module for Containers | golang-github-docker-libnetwork | Released |
SUSE Linux Enterprise 12 Module for Containers | runc | In progress |
SUSE Linux Enterprise 15 Module for Containers | docker-runc | Released |
SUSE Linux Enterprise 15-SP1 Module for Containers | containerd | Released |
SUSE Linux Enterprise 15-SP1 Module for Containers | docker | Released |
SUSE Linux Enterprise 15-SP1 Module for Containers | docker-runc | Released |
SUSE Linux Enterprise 15-SP1 Module for Containers | golang-github-docker-libnetwork | Released |
SUSE Linux Enterprise 15-SP1 Module for Containers | runc | Released |
SUSE Linux Enterprise 15-SP2 Module for Containers | containerd | Released |
SUSE Linux Enterprise 15-SP2 Module for Containers | docker | Released |
SUSE Linux Enterprise 15-SP2 Module for Containers | docker-runc | Released |
SUSE Linux Enterprise 15-SP2 Module for Containers | golang-github-docker-libnetwork | Released |
SUSE Linux Enterprise 15-SP2 Module for Containers | runc | Released |
SUSE OpenStack Cloud 6 LTSS | docker-runc | Released |
SUSE OpenStack Cloud 6 LTSS | runc | Affected |