Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade docker.io | Jul 30, 2024 | May 18, 2015 |
| Oracle_linux | — | Upgrade docker-pkg-develUpgrade dockerUpgrade docker-logrotateUpgrade docker-vimUpgrade docker-zsh-completionUpgrade docker-devel | Oct 16, 2024 | May 18, 2015 |
| Suse | — | Upgrade dockerUpgrade docker-bash-completionUpgrade docker-fish-completion | Dec 18, 2015 | May 18, 2015 |
| Ubuntu | — | Upgrade docker.io | Nov 19, 2024 | May 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub