runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
{
"unresolved_ranges": [
{
"vendor_product": "canonical:ubuntu_linux",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "16.04"
},
{
"last_affected": "18.10"
},
{
"last_affected": "19.04"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "d2iq:dc/os",
"cpes": [
"cpe:2.3:o:d2iq:dc\\/os:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "1.10.10"
},
{
"introduced": "1.10.11"
},
{
"fixed": "1.11.9"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "d2iq:kubernetes_engine",
"cpes": [
"cpe:2.3:a:d2iq:kubernetes_engine:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "2.2.0-1.13.3"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "docker:docker",
"cpes": [
"cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "18.09.2"
},
{
"fixed": "18.09.2"
},
{
"fixed": "18.09.2"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "29"
},
{
"last_affected": "30"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "microfocus:service_management_automation",
"cpes": [
"cpe:2.3:a:microfocus:service_management_automation:2018.02:*:*:*:*:*:*:*",
"cpe:2.3:a:microfocus:service_management_automation:2018.05:*:*:*:*:*:*:*",
"cpe:2.3:a:microfocus:service_management_automation:2018.08:*:*:*:*:*:*:*",
"cpe:2.3:a:microfocus:service_management_automation:2018.11:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "2018.02"
},
{
"last_affected": "2018.05"
},
{
"last_affected": "2018.08"
},
{
"last_affected": "2018.11"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "opensuse:backports_sle",
"cpes": [
"cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*",
"cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.0-NA"
},
{
"last_affected": "15.0-sp1"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "opensuse:leap",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "15.1"
},
{
"last_affected": "42.3"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "redhat:container_development_kit",
"cpes": [
"cpe:2.3:a:redhat:container_development_kit:3.7:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "3.7"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "redhat:enterprise_linux",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "8.0"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "redhat:enterprise_linux_server",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "7.0"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "redhat:openshift",
"cpes": [
"cpe:2.3:a:redhat:openshift:3.4:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.5:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "3.4"
},
{
"last_affected": "3.5"
}
],
"source": "CPE_FIELD"
}
]
}