cbcvebase.
CVE-2019-19921
published 2020-02-12

CVE-2019-19921: runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker…

PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.46%
36.8th percentile
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianrunc< runc 1.1.5+ds1-1 (bookworm)runc 1.1.5+ds1-1 (bookworm)
debianrunc< runc 1.0.0~rc10+dfsg1-1 (bookworm)runc 1.0.0~rc10+dfsg1-1 (bookworm)
debianrunc< runc 1.3.3+ds1-2 (forky)runc 1.3.3+ds1-2 (forky)
github.comopencontainers_runc>= 0 < 1.2.81.2.8
github.comopencontainers_runc>= 0 < 1.0.0-rc9.0.20200122160610-2fc03cc11c771.0.0-rc9.0.20200122160610-2fc03cc11c77
github.comopencontainers_runc>= 1.0.0-rc95 < 1.1.51.1.5
github.comopencontainers_runc>= 1.3.0-rc.1 < 1.3.31.3.3
github.comopencontainers_runc>= 1.4.0-rc.1 < 1.4.0-rc.31.4.0-rc.3
github.comopencontainers_selinux>= 0 < 1.13.01.13.0
github.comsylabs_singularity_v4>= 0 < 4.1.114.1.11
github.comsylabs_singularity_v4>= 4.2.0-rc.1 < 4.3.54.3.5
linuxfoundationrunc< 1.2.81.2.8
linuxfoundationrunc< 1.1.51.1.5
linuxfoundationrunc<= 0.1.1
linuxfoundationrunc
linuxfoundationrunc
linuxfoundationrunc>= 0 < 1.0.0~rc93+ds1-5+deb11u51.0.0~rc93+ds1-5+deb11u5
linuxfoundationrunc>= 0 < 1.0.0~rc10+dfsg1-11.0.0~rc10+dfsg1-1
linuxfoundationrunc>= 0 < 1.1.5+ds1-11.1.5+ds1-1
linuxfoundationrunc>= 0 < 1.0.0~rc10+dfsg1-11.0.0~rc10+dfsg1-1
linuxfoundationrunc>= 0 < 1.1.5+ds1-11.1.5+ds1-1

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
ghsa7.3HIGH
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.