Wind River Support Network

HomeDefectsLIN1019-4041
Fixed

LIN1019-4041 : Security Advisory - runc-opencontainers - CVE-2019-19921

Created: Feb 16, 2020    Updated: May 21, 2023
Resolved Date: May 16, 2023
Found In Version: 10.19.45.1
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

CVEs


Live chat
Online