Back to search
CVE-2019-16884
Published: Sep 25, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2019-bd4843561c
vendor-advisory
FEDORA-2019-3fc86a518b
vendor-advisory
FEDORA-2019-96946c39dd
vendor-advisory
openSUSE-SU-2019:2418
vendor-advisory
openSUSE-SU-2019:2434
vendor-advisory
RHSA-2019:3940
vendor-advisory
RHSA-2019:4074
vendor-advisory
RHSA-2019:4269
vendor-advisory
openSUSE-SU-2020:0045
vendor-advisory
GLSA-202003-21
vendor-advisory
USN-4297-1
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now