Total vulnerabilities in the database
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
Software | From | Fixed in |
---|---|---|
linuxfoundation / runc | - | 1.1.5 |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / openshift_container_platform | 4.0 | 4.0.x |
redhat / enterprise_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
![]() |
1.0.0-rc95 | 1.1.5 |