7

CVE-2019-19921

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linuxfoundation ≫ Runc Version <= 0.1.1
Linuxfoundation ≫ Runc Version 1.0.0 Update rc1
Linuxfoundation ≫ Runc Version 1.0.0 Update rc2
Linuxfoundation ≫ Runc Version 1.0.0 Update rc3
Linuxfoundation ≫ Runc Version 1.0.0 Update rc4
Linuxfoundation ≫ Runc Version 1.0.0 Update rc5
Linuxfoundation ≫ Runc Version 1.0.0 Update rc6
Linuxfoundation ≫ Runc Version 1.0.0 Update rc7
Linuxfoundation ≫ Runc Version 1.0.0 Update rc8
Linuxfoundation ≫ Runc Version 1.0.0 Update rc9
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Opensuse ≫ Leap Version 15.1
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.354
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://security.gentoo.org/glsa/202003-21
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/03/msg00023.html
https://usn.ubuntu.com/4297-1/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00018.html
Third Party Advisory
Broken Link
Mailing List
https://access.redhat.com/errata/RHSA-2020:0688
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0695
Third Party Advisory
https://github.com/opencontainers/runc/issues/2197
Patch
Third Party Advisory
Issue Tracking
https://github.com/opencontainers/runc/pull/2190
Third Party Advisory
Issue Tracking
https://github.com/opencontainers/runc/releases
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ANUGDBJ7NBUMSUFZUSKU3ZMQYZ2Z3STN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHGVGGMKGZSJ7YO67TGGPFEHBYMS63VF/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNB2UEDIIJCRQW4WJLZOPQJZXCVSXMLD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FYVE3GB4OG3BNT5DLQHYO4M5SXX33AQ5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I6BF24VCZRFTYBTT3T7HDZUOTKOTNPLZ/
https://security-tracker.debian.org/tracker/CVE-2019-19921
Third Party Advisory