CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and conseq… (CVE-2019-5736)
Description
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Metrics
Affected operating systems
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux_server7.0
linux
opensuse / leap15.0
linux
opensuse / leap15.1
linux
opensuse / leap42.3
linux
canonical / ubuntu_linux16.04
linux
canonical / ubuntu_linux18.04
linux
canonical / ubuntu_linux18.10
linux
canonical / ubuntu_linux19.04
other
d2iq / dc\/os
other
fedoraproject / fedora29
other
fedoraproject / fedora30
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
apache
mesos1.4.0 – 1.4.3
apache
mesos1.5.0 – 1.5.3
apache
mesos1.6.0 – 1.6.2
apache
mesos1.7.0 – 1.7.2
d2iq
kubernetes_engine2.2.0-1.13.3
docker
docker18.09.2
google
kubernetes_engine
hp
onesphere
linuxcontainers
lxc3.2.0
linuxfoundation
runc0.1.1
linuxfoundation
runc
microfocus
service_management_automation
netapp
hci_management_node
netapp
solidfire
opensuse
backports_sle
redhat
container_development_kit
redhat
openshift
References & sources
- https://github.com/opencontainers/runc/commit/6635b4f0c6af3810594d2770f662f34ddc15b40d
- https://access.redhat.com/errata/RHSA-2019:0408vendor-advisory
- https://github.com/rancher/runc-cve
- https://access.redhat.com/errata/RHSA-2019:0401vendor-advisory
- https://github.com/docker/docker-ce/releases/tag/v18.09.2
- https://www.synology.com/security/advisory/Synology_SA_19_06
- https://security.netapp.com/advisory/ntap-20190307-0008/
- https://access.redhat.com/errata/RHSA-2019:0303vendor-advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190215-runcvendor-advisory
- https://github.com/q3k/cve-2019-5736-poc
- https://www.exploit-db.com/exploits/46359/exploit
- https://github.com/opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b
- https://aws.amazon.com/security/security-bulletins/AWS-2019-002/
- https://www.openwall.com/lists/oss-security/2019/02/11/2
- https://kubernetes.io/blog/2019/02/11/runc-and-cve-2019-5736/
- https://access.redhat.com/security/cve/cve-2019-5736
- https://www.exploit-db.com/exploits/46369/exploit
- https://access.redhat.com/errata/RHSA-2019:0304vendor-advisory
- https://github.com/Frichetten/CVE-2019-5736-PoC
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03913en_us