CVE-2018-10892
06.07.2018, 16:29
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.Enginsight
Vendor | Product | Version |
---|---|---|
docker | docker | 1.11 ≤ 𝑥 ≤ 18.03.1 |
docker | docker | 1.11 ≤ 𝑥 ≤ 18.03.1 |
mobyproject | moby | 1.11 ≤ 𝑥 ≤ 17.03.2 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux_server | 7.0 |
opensuse | leap | 15.0 |
opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References