cbcvebase.
CVE-2019-5736
published 2019-02-11

CVE-2019-5736: runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host…

high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EXPLOIT
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
apachemesos>= 1.4.0 < 1.4.31.4.3
apachemesos>= 1.5.0 < 1.5.31.5.3
apachemesos>= 1.6.0 < 1.6.21.6.2
apachemesos>= 1.7.0 < 1.7.21.7.2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
d2iqdc_os< 1.10.101.10.10
d2iqdc_os>= 1.10.11 < 1.11.91.11.9
d2iqdc_os>= 1.11.10 < 1.12.11.12.1
d2iqkubernetes_engine< 2.2.0-1.13.32.2.0-1.13.3
debiandocker.io
debianfirejail< firejail 0.9.58.2-2 (bookworm)firejail 0.9.58.2-2 (bookworm)
debianlxc< lxc 1:3.1.0+really3.0.3-4 (bookworm)lxc 1:3.1.0+really3.0.3-4 (bookworm)
debianrunc< lxc 1:3.1.0+really3.0.3-4 (bookworm)lxc 1:3.1.0+really3.0.3-4 (bookworm)
dockerdocker< 18.09.218.09.2
dockerdocker
dockerdocker
fedoraprojectfedora
fedoraprojectfedora
firejail_projectfirejail< 0.9.600.9.60
firejail_projectfirejail>= 0 < 0.9.58.2-20.9.58.2-2
firejail_projectfirejail>= 0 < 0.9.58.2-20.9.58.2-2
firejail_projectfirejail>= 0 < 0.9.58.2-20.9.58.2-2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.6HIGH
vulncheck8.6HIGH