CVE-2019-5736
11.02.2019, 19:29
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Vendor | Product | Version |
---|---|---|
docker | docker | 𝑥 < 18.09.2 |
linuxfoundation | runc | 𝑥 ≤ 0.1.1 |
linuxfoundation | runc | 1.0.0:rc1 |
linuxfoundation | runc | 1.0.0:rc2 |
linuxfoundation | runc | 1.0.0:rc3 |
linuxfoundation | runc | 1.0.0:rc4 |
linuxfoundation | runc | 1.0.0:rc5 |
linuxfoundation | runc | 1.0.0:rc6 |
redhat | container_development_kit | 3.7 |
redhat | openshift | 3.4 |
redhat | openshift | 3.5 |
redhat | openshift | 3.6 |
redhat | openshift | 3.7 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux_server | 7.0 |
kubernetes_engine | - | |
linuxcontainers | lxc | 𝑥 < 3.2.0 |
hp | onesphere | - |
netapp | hci_management_node | - |
netapp | solidfire | - |
apache | mesos | 1.4.0 ≤ 𝑥 < 1.4.3 |
apache | mesos | 1.5.0 ≤ 𝑥 < 1.5.3 |
apache | mesos | 1.6.0 ≤ 𝑥 < 1.6.2 |
apache | mesos | 1.7.0 ≤ 𝑥 < 1.7.2 |
opensuse | backports_sle | 15.0 |
opensuse | backports_sle | 15.0:sp1 |
opensuse | leap | 15.0 |
opensuse | leap | 15.1 |
opensuse | leap | 42.3 |
d2iq | kubernetes_engine | 𝑥 < 2.2.0-1.13.3 |
d2iq | dc\/os | 𝑥 < 1.10.10 |
d2iq | dc\/os | 1.10.11 ≤ 𝑥 < 1.11.9 |
d2iq | dc\/os | 1.11.10 ≤ 𝑥 < 1.12.1 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
canonical | ubuntu_linux | 19.04 |
microfocus | service_management_automation | 2018.02 |
microfocus | service_management_automation | 2018.05 |
microfocus | service_management_automation | 2018.08 |
microfocus | service_management_automation | 2018.11 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
lxc |
| ||||||||||||
runc |
|

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
docker.io |
| ||||||||||
runc |
|
References