← All CVEs

CVE-2019-5736

high · 8.6

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

8.6
CVSS
98.5%
EPSS (exploit prob.)
100th
EPSS percentile
2019-02-11
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
dockerdocker< 18.09.2
linuxfoundationrunc<= 0.1.1
linuxfoundationrunc1.0.0
linuxfoundationrunc1.0.0
linuxfoundationrunc1.0.0
linuxfoundationrunc1.0.0
linuxfoundationrunc1.0.0
linuxfoundationrunc1.0.0
redhatcontainer_development_kit3.7
redhatopenshift3.4
redhatopenshift3.5
redhatopenshift3.6
redhatopenshift3.7
redhatenterprise_linux8.0
redhatenterprise_linux_server7.0
googlekubernetes_engineall versions
linuxcontainerslxc< 3.2.0
hponesphereall versions
netapphci_management_nodeall versions
netappsolidfireall versions
apachemesos>= 1.4.0, < 1.4.3
apachemesos>= 1.5.0, < 1.5.3
apachemesos>= 1.6.0, < 1.6.2
apachemesos>= 1.7.0, < 1.7.2
opensusebackports_sle15.0
opensusebackports_sle15.0
opensuseleap15.0
opensuseleap15.1
opensuseleap42.3
d2iqkubernetes_engine< 2.2.0-1.13.3
d2iqdc/os< 1.10.10
d2iqdc/os>= 1.10.11, < 1.11.9
d2iqdc/os>= 1.11.10, < 1.12.1
fedoraprojectfedora29
fedoraprojectfedora30
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux18.10
canonicalubuntu_linux19.04
microfocusservice_management_automation2018.02

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-5736