peter bassill · operator
$ cve CVE-2019-5736 JSON

CVE-2019-5736 EXPLOIT

8.6
HIGH · CVSS 3.1 · EPSS 98.5% (pctl 100)

Patch early

A public exploit exists.

Description

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

Scoring

CVSS8.6 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS98.45% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2019-02-11
Last modified2026-06-17

Affected (19)

VendorProduct
apachemesos
canonicalubuntu linux
d2iqdc\/os
d2iqkubernetes engine
dockerdocker
fedoraprojectfedora
googlekubernetes engine
hponesphere
linuxcontainerslxc
linuxfoundationrunc
microfocusservice management automation
netapphci management node
netappsolidfire
opensusebackports sle
opensuseleap
redhatcontainer development kit
redhatenterprise linux
redhatenterprise linux server
redhatopenshift

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD