libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade runc | Jul 30, 2024 | Jun 1, 2016 |
| Docker | — | Upgrade to Docker v1.12.2 | May 4, 2017 | Jun 1, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/docker. | Oct 30, 2017 | Jun 1, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade docker-engineUpgrade docker-engine-selinux | Nov 30, 2017 | Jun 1, 2016 |
| Oracle_linux | — | Upgrade docker-engine-selinuxUpgrade docker-engine | Jun 1, 2016 | Jun 1, 2016 |
| Redhat_linux | — | Upgrade docker-commonUpgrade dockerUpgrade docker-lvm-pluginUpgrade docker-novolume-pluginUpgrade docker-selinuxUpgrade docker-logrotateUpgrade docker-v1.10-migratorUpgrade docker-forward-journaldUpgrade docker-rhel-push-plugin | Oct 6, 2017 | Jun 1, 2016 |
| Suse | — | Upgrade docker-fish-completionUpgrade dockerUpgrade docker-bash-completion | May 31, 2016 | Apr 26, 2016 |
| Ubuntu | — | Upgrade runc | Nov 19, 2024 | Jun 1, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub