PT-2015-6250 · Docker+2 · Docker Engine+3

Eric Windisch

·

Published

2015-05-08

·

Updated

2025-10-11

·

CVE-2015-3630

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker Engine versions prior to 1.6.1
Description The issue allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image. This is due to weak permissions for certain /proc files, including /proc/asound, /proc/timer stats, /proc/latency stats, and /proc/fs.
Recommendations For Docker Engine versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable /proc files to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1429
CVE-2015-3630
GHSA-8FVR-5RQF-3WWH
GO-2022-0638
OPENSUSE-SU-2024:10532-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2015:0984-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1

Affected Products

Alt Linux
Docker
Docker Engine
Suse