CVE-2019-5736

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and conseq… (CVE-2019-5736)

Description

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

Source: CVELISTV5NVD

Metrics

Severity
high
no public PoC known
8.6
Source: nvd-v3
99.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
98.5 %
High — model estimates ≥ 50% chance of real-world exploitation within 30 days.
Published
2019-02-11 00:00 UTC

Affected operating systems

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux_server7.0

  • linux

    opensuse / leap15.0

  • linux

    opensuse / leap15.1

  • linux

    opensuse / leap42.3

  • linux

    canonical / ubuntu_linux16.04

  • linux

    canonical / ubuntu_linux18.04

  • linux

    canonical / ubuntu_linux18.10

  • linux

    canonical / ubuntu_linux19.04

  • other

    d2iq / dc\/os

  • other

    fedoraproject / fedora29

  • other

    fedoraproject / fedora30

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    mesos1.4.0 – 1.4.3

  • apache

    mesos1.5.0 – 1.5.3

  • apache

    mesos1.6.0 – 1.6.2

  • apache

    mesos1.7.0 – 1.7.2

  • d2iq

    kubernetes_engine2.2.0-1.13.3

  • docker

    docker18.09.2

  • google

    kubernetes_engine

  • hp

    onesphere

  • linuxcontainers

    lxc3.2.0

  • linuxfoundation

    runc0.1.1

  • linuxfoundation

    runc

  • microfocus

    service_management_automation

  • netapp

    hci_management_node

  • netapp

    solidfire

  • opensuse

    backports_sle

  • redhat

    container_development_kit

  • redhat

    openshift

References & sources

IDCVE-2019-5736