CVE-2018-20699
published 2019-01-12CVE-2018-20699: Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus…
PriorityP419medium4.9CVSS 3.0
AVNACLPRHUINSUCNINAH
EPSS
2.23%
81.0th percentile
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | docker.io | < docker.io 18.09.1+dfsg1-2 (bookworm) | docker.io 18.09.1+dfsg1-2 (bookworm) |
| docker | engine | < 18.09 | 18.09 |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m9q8-9m2h-84gh: Docker Engine before 18
ghsa_unreviewed·2022-05-14
CVE-2018-20699 [MEDIUM] CWE-400 GHSA-m9q8-9m2h-84gh: Docker Engine before 18
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
OSV
CVE-2018-20699: Docker Engine before 18
osv·2019-01-12·CVSS 4.9
CVE-2018-20699 [MEDIUM] CVE-2018-20699: Docker Engine before 18
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Red Hat
docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus
vendor_redhat·2018-10-04·CVSS 4.9
CVE-2018-20699 [MEDIUM] CWE-400 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus
docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Statement: This issue affects the versions of docker as shipped with Red Hat Enterprise Linux 7, however if docker is accessible only by root or highly privileged users, as it is by default, a low-privileged attacker will not be able to trigger the flaw.
Debian
CVE-2018-20699: docker.io - Docker Engine before 18.09 allows attackers to cause a denial of service (docker...
vendor_debian·2018·CVSS 4.9
CVE-2018-20699 [MEDIUM] CVE-2018-20699: docker.io - Docker Engine before 18.09 allows attackers to cause a denial of service (docker...
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Scope: local
bookworm: resolved (fixed in 18.09.1+dfsg1-2)
bullseye: resolved (fixed in 18.09.1+dfsg1-2)
forky: resolved (fixed in 18.09.1+dfsg1-2)
sid: resolved (fixed in 18.09.1+dfsg1-2)
trixie: resolved (fixed in 18.09.1+dfsg1-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
bugzilla·2019-01-19·CVSS 4.9
CVE-2018-20699 [MEDIUM] CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
+++ This bug was initially created as a clone of Bug #1666566 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in
Bugzilla
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus
bugzilla·2019-01-16·CVSS 4.9
CVE-2018-20699 [MEDIUM] CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
References:
https://github.com/docker/engine/pull/70
https://github.com/moby/moby/pull/37967
Discussion:
Created docker tracking bugs for this issue:
Affects: epel-6 [bug 1666568]
Affects: fedora-all [bug 1666566]
Created docker:2017.0/docker tracking bugs for this issue:
Affects: fedora-all [bug 1666567]
---
Fixed via https://github.com/projectatomic/docker/commit/11e17d3b79bc450a52d5e1dd1c1444f7ebe5f751
---
Function isCpusetListA
Bugzilla
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
bugzilla·2019-01-16·CVSS 4.9
CVE-2018-20699 [MEDIUM] CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-20699 docker:2017.0/docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
bugzilla·2019-01-16·CVSS 4.9
CVE-2018-20699 [MEDIUM] CVE-2018-20699 docker:2017.0/docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
CVE-2018-20699 docker:2017.0/docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [epel-6]
bugzilla·2019-01-16·CVSS 4.9
CVE-2018-20699 [MEDIUM] CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [epel-6]
CVE-2018-20699 docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the foll
2019-01-12
Published