CVE-2019-14271
9.8
CRITICAL · CVSS 3.1 · EPSS 18.8% (pctl 97)
Patch early
EPSS 18.8% — above the 10% action threshold.
Description
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 18.83% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-665 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-07-29 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| debian | debian linux |
| docker | docker |
| opensuse | leap |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html
- https://docs.docker.com/engine/release-notes/
- https://github.com/moby/moby/issues/39449
- https://seclists.org/bugtraq/2019/Sep/21
- https://security.netapp.com/advisory/ntap-20190828-0003/
- https://www.debian.org/security/2019/dsa-4521
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html
- https://docs.docker.com/engine/release-notes/
- https://github.com/moby/moby/issues/39449
- https://seclists.org/bugtraq/2019/Sep/21
- https://security.netapp.com/advisory/ntap-20190828-0003/
- https://www.debian.org/security/2019/dsa-4521
→ the Explorer · watch your stack · NVD