CVE-2020-14300
published 2020-07-13CVE-2020-14300: The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053…
PriorityP347high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.38%
30.3th percentile
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of the container. This could lead to compromise of the container host or other containers running on the same container host. This issue only affects a single version of Docker, 1.13.1-108.git4ef4b30, shipped in Red Hat Enterprise Linux 7. Both earlier and later versions are not affected.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | docker.io | — | — |
| docker | docker | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
docker: Security regression of CVE-2016-9962 due to inclusion of vulnerable runc
vendor_redhat·2020-06-23·CVSS 6.4
CVE-2020-14300 [MEDIUM] CWE-271 docker: Security regression of CVE-2016-9962 due to inclusion of vulnerable runc
docker: Security regression of CVE-2016-9962 due to inclusion of vulnerable runc
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compro
Debian
CVE-2020-14300: docker.io - The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red...
vendor_debian·2020·CVSS 6.4
CVE-2020-14300 [MEDIUM] CVE-2020-14300: docker.io - The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red...
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of
GHSA
GHSA-26mh-fmrh-48w9: The docker packages version docker-1
ghsa_unreviewed·2022-05-24·CVSS 6.4
CVE-2020-14300 [MEDIUM] CWE-273 GHSA-26mh-fmrh-48w9: The docker packages version docker-1
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHBA-2020:0427https://access.redhat.com/security/cve/CVE-2016-9962https://access.redhat.com/security/vulnerabilities/cve-2016-9962https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9962https://access.redhat.com/errata/RHBA-2020:0427https://access.redhat.com/security/cve/CVE-2016-9962https://access.redhat.com/security/vulnerabilities/cve-2016-9962https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9962
2020-07-13
Published