PT-2017-4094 · Open Container Initiative+3 · Runc+3
Aleksa Sarai
+1
·
Published
2017-01-30
·
Updated
2025-10-11
·
CVE-2016-9962
CVSS v3.1
6.4
Medium
| Vector | AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
runc (affected versions not specified)
Description
The issue is related to a flaw in tracking additional container processes using the container's pid 1, which can be exploited to gain access to sensitive data, compromise data integrity, and cause a denial of service. Specifically, the vulnerability allows the main processes of the container, if running as root, to gain access to file-descriptors of new processes during initialization, potentially leading to container escapes or modification of the runC state before the process is fully placed inside the container.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Docker
Suse
Runc