cbcvebase.
CVE-2019-16884
published 2019-09-25

CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go…

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiangolang-github-opencontainers-selinux< golang-github-opencontainers-selinux 1.3.0-2 (bookworm)golang-github-opencontainers-selinux 1.3.0-2 (bookworm)
debianrunc< golang-github-opencontainers-selinux 1.3.0-2 (bookworm)golang-github-opencontainers-selinux 1.3.0-2 (bookworm)
dockerdocker<= 19.03.2
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
github.comopencontainers_runc>= 0 < 1.0.0-rc8.0.20190930145003-cad42f6e09321.0.0-rc8.0.20190930145003-cad42f6e0932
github.comopencontainers_selinux>= 0 < 1.3.1-0.20190929122143-5215b1806f521.3.1-0.20190929122143-5215b1806f52
linuxfoundationrunc
linuxfoundationrunc>= 0 < 1.0.0~rc9+dfsg1-11.0.0~rc9+dfsg1-1
linuxfoundationrunc>= 0 < 1.0.0~rc9+dfsg1-11.0.0~rc9+dfsg1-1
linuxfoundationrunc>= 0 < 1.0.0~rc9+dfsg1-11.0.0~rc9+dfsg1-1
linuxfoundationrunc>= 0 < 1.0.0~rc9+dfsg1-11.0.0~rc9+dfsg1-1
linuxfoundationrunc>= 0 < 1.0.0~rc10-0ubuntu1~18.04.21.0.0~rc10-0ubuntu1~18.04.2
linuxfoundationrunc>= 0 < 1.0.0~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm21.0.0~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm2
linuxfoundationrunc0.0.1 – 0.1.1
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_moby-buildx_0.4.1+azure-3_on_cbl_mariner_1.0
opensuseleap
opensuseleap
redhatenterprise_linux
redhatenterprise_linux_eus

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH