Vulnerability Database

310,710

Total vulnerabilities in the database

CVE-2016-9962

RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.

CVSS v2:

  • Severity: Low
  • Score: 4.4
  • AV:L/AC:M/Au:N/C:P/I:P/A:P
Software From Fixed in
docker / docker 1.11.0 1.12.6
Go icon github.com/opencontainers/runc - 1.0.0-rc3