PT-2019-1439 · Open Container Initiative+8 · Runc+8

Adam Iwaniuk

+1

·

Published

2016-08-03

·

Updated

2026-01-19

·

CVE-2019-5736

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions runc versions prior to 1.0-rc6 Docker versions prior to 18.09.2
Description The issue is related to file-descriptor mishandling in the runc tool, which can be exploited to execute arbitrary code. This can allow an attacker to overwrite the host runc binary and gain root access. The vulnerability can be exploited by executing a command as root within a container, either by creating a new container with an attacker-controlled image or by attaching to an existing container with docker exec. The vulnerability affects Azure Container Instances (ACI) and can be used to escape from a container and gain access to other containers in the same cluster.
Recommendations For runc versions prior to 1.0-rc6: Update to a version later than 1.0-rc6 to fix the file-descriptor mishandling issue. For Docker versions prior to 18.09.2: Update to a version later than 18.09.2 to ensure that the runc tool is updated to a secure version. As a temporary workaround, consider disabling the execution of commands as root within containers to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:0975
ALSA-2019_0975
ALSA-2019_4269
ALSA-2020_1650
ALSA-2021_2291
ALSA-2021_2370
ALSA-2021_2371
ALSA-2025_16880
ALT-PU-2016-1817
ALT-PU-2019-1215
ALT-PU-2019-1217
ALT-PU-2019-1229
ALT-PU-2019-1230
ALT-PU-2019-1233
ALT-PU-2020-1651
ALT-PU-2020-1772
BDU:2019-00826
CESA-2019_0975
CVE-2019-5736
ELSA-2019-0975
ELSA-2019-4540
ELSA-2019-4550
ELSA-2019-4551
ELSA-2021-9203
MGASA-2019-0068
MGASA-2019-0087
OPENSUSE-SU-2019:0170-1
OPENSUSE-SU-2019:0208-1
OPENSUSE-SU-2019:0252-1
OPENSUSE-SU-2019:0295-1
OPENSUSE-SU-2019:1227-1
OPENSUSE-SU-2019:1275-1
OPENSUSE-SU-2019:1444-1
OPENSUSE-SU-2019:1499-1
OPENSUSE-SU-2019:1506-1
OPENSUSE-SU-2019:2021-1
OPENSUSE-SU-2019:2245-1
OPENSUSE-SU-2019:2286-1
OPENSUSE-SU-2019_0201-1
OPENSUSE-SU-2019_0208-1
OPENSUSE-SU-2019_0252-1
OPENSUSE-SU-2019_0295-1
OPENSUSE-SU-2019_1079-1
OPENSUSE-SU-2019_1275-1
OPENSUSE-SU-2019_1444-1
OPENSUSE-SU-2019_1481-1
OPENSUSE-SU-2019_1499-1
OPENSUSE-SU-2019_2021-1
OPENSUSE-SU-2019_2245-1
OPENSUSE-SU-2024:10693-1
OPENSUSE-SU-2024:10762-1
OPENSUSE-SU-2024:11030-1
OPENSUSE-SU-2024:11358-1
RHSA-2019:0303
RHSA-2019:0304
RHSA-2019:0408
RHSA-2019:0975
RHSA-2019_0975
RLSA-2019:0975
RLSA-2019_0975
SUSE-SU-2019:0362-1
SUSE-SU-2019:0385-1
SUSE-SU-2019:0495-1
SUSE-SU-2019:0573-1
SUSE-SU-2019:1234-1
SUSE-SU-2019:1234-2
SUSE-SU-2019:2117-1
SUSE-SU-2019:2119-1
SUSE-SU-2019_0362-1
SUSE-SU-2019_0385-1
SUSE-SU-2019_0495-1
SUSE-SU-2019_0573-1
SUSE-SU-2019_1234-1
SUSE-SU-2019_1234-2
SUSE-SU-2019_2117-1
SUSE-SU-2019_2119-1
SUSE-SU-2021:1458-1
SUSE-SU-2021_1458-1
USN-4048-1

Affected Products

Alt Linux
Almalinux
Centos
Docker
Red Hat
Rocky Linux
Suse
Ubuntu
Runc