An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade docker | Aug 22, 2024 | Jun 2, 2020 |
| Amazon Linux Ami 2 | — | Upgrade docker-debuginfoUpgrade docker | Jul 4, 2022 | Jun 2, 2020 |
| Amazon_linux | — | Upgrade docker | Jun 4, 2020 | Jun 2, 2020 |
| Debian | — | Upgrade docker.io | Jul 6, 2020 | Jun 2, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/docker. | Aug 27, 2020 | Jun 2, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade docker-engine-selinuxUpgrade docker-engine | Jul 31, 2020 | Jun 2, 2020 |
| Oracle_linux | — | Upgrade docker-engineUpgrade docker-cli | Jun 13, 2020 | Jun 1, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2020 |
| Suse | — | Upgrade docker-fish-completionUpgrade docker-bash-completionUpgrade containerdUpgrade docker-runcUpgrade dockerUpgrade golang-github-docker-libnetworkUpgrade docker-testUpgrade docker-zsh-completionUpgrade docker-libnetworkUpgrade containerd-ctr | Jun 24, 2020 | Jun 2, 2020 |
| Ubuntu | — | Upgrade docker.io | Nov 19, 2024 | Jun 2, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 2, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub