cbcvebase.
CVE-2019-5736
published 2019-02-11

CVE-2019-5736: runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host…

PriorityP185high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
98.57%
99.9th percentile
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
apachemesos>= 1.4.0 < 1.4.31.4.3
apachemesos>= 1.5.0 < 1.5.31.5.3
apachemesos>= 1.6.0 < 1.6.21.6.2
apachemesos>= 1.7.0 < 1.7.21.7.2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
d2iqdc_os< 1.10.101.10.10
d2iqdc_os>= 1.10.11 < 1.11.91.11.9
d2iqdc_os>= 1.11.10 < 1.12.11.12.1
d2iqkubernetes_engine< 2.2.0-1.13.32.2.0-1.13.3
debiandocker.io
debianfirejail< firejail 0.9.58.2-2 (bookworm)firejail 0.9.58.2-2 (bookworm)
debianlxc< lxc 1:3.1.0+really3.0.3-4 (bookworm)lxc 1:3.1.0+really3.0.3-4 (bookworm)
debianrunc< lxc 1:3.1.0+really3.0.3-4 (bookworm)lxc 1:3.1.0+really3.0.3-4 (bookworm)
dockerdocker< 18.09.218.09.2
dockerdocker
dockerdocker
fedoraprojectfedora
fedoraprojectfedora
firejail_projectfirejail< 0.9.600.9.60
firejail_projectfirejail>= 0 < 0.9.58.2-20.9.58.2-2
firejail_projectfirejail>= 0 < 0.9.58.2-20.9.58.2-2
firejail_projectfirejail>= 0 < 0.9.58.2-20.9.58.2-2

Detection & IOCsextracted from sources · hover to see the quote

ip185.144.101[.]201
urlhttp://185.144.101[.]201/xmrig
urlhttp://185.144.101[.]201/222.json
path/var/tmp/xmrig
path/var/tmp/config.json
commanddocker run -it --privileged --pid=host --net=host docker sh -c nsenter --mount=/proc/1/ns/mnt -- su -
versiondocker-1.13.1-108.git4ef4b30.el7
  • Detect CVE-2019-5736 exploitation attempts via BOtB tool performing container breakout; monitor for BOtB process execution inside containers.
  • Alert on containers launched with --privileged --pid=host --net=host flags combined with nsenter execution, which is a known host escape technique exploitable in the context of CVE-2019-5736.
  • ·Only docker version 1.13.1-108.git4ef4b30.el7 on RHEL 7 Extras is affected by the missing CVE-2019-5736 fix; earlier and later versions of the RHEL docker package are not affected.
  • ·Standard Kubernetes deployments allow anonymous kubelet access by default; most managed services (AKS, GKE, Kops) enforce authentication by default, reducing exposure.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.6HIGH
vulncheck8.6HIGH
vendor_debian8.6LOW
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.