CVE-2019-19921

Name
CVE-2019-19921
Description
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://github.com/opencontainers/runc/issues/2197
Issue Tracking https://github.com/opencontainers/runc/pull/2190
Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2019-19921
Third Party Advisory https://github.com/opencontainers/runc/releases
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00018.html
REDHAT https://access.redhat.com/errata/RHSA-2020:0688
REDHAT https://access.redhat.com/errata/RHSA-2020:0695
GENTOO https://security.gentoo.org/glsa/202003-21
UBUNTU https://usn.ubuntu.com/4297-1/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* runc >= None <= 0.1.1
cpe:2.3:a:linuxfoundation:runc:1.0.0:rc1:*:*:*:*:*:* runc == None == 1.0.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
runc edge-community 1.0.0_rc10-r0 None fixed
runc edge-community 1.0.0-r0 Jake Buchholz <tomalok@gmail.com> fixed
runc 3.22-community 1.0.0_rc10-r0 None fixed
runc 3.21-community 1.0.0_rc10-r0 None fixed
runc 3.20-community 1.0.0_rc10-r0 None fixed
runc 3.19-community 1.0.0_rc10-r0 None fixed
runc 3.18-community 1.0.0_rc10-r0 None fixed
runc 3.17-community 1.0.0_rc10-r0 None fixed
containerd edge-community 1.3.3-r0 None fixed
containerd 3.22-community 1.3.3-r0 None fixed
containerd 3.21-community 1.3.3-r0 None fixed
containerd 3.20-community 1.3.3-r0 None fixed
containerd 3.19-community 1.3.3-r0 None fixed
containerd 3.18-community 1.3.3-r0 None fixed
containerd 3.17-community 1.3.3-r0 None fixed