CVE-2016-9962
Last modified
CVE-2016-9962 is a vulnerability of currently unknown severity. RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Docker | Docker | >= 1.11.0, < 1.12.6 |
References
- http://seclists.org/fulldisclosure/2017/Jan/21Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Jan/29Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/95361Third Party Advisory, VDB Entry
- https://access.redhat.com/security/vulnerabilities/cve-2016-9962Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1012568#c6Issue Tracking
- https://github.com/docker/docker/releases/tag/v1.12.6Vendor Advisory
- https://github.com/opencontainers/runc/commit/50a19c6ff828c58e5dab13830bd3dacde268afe5Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201701-34Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Jan/21Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Jan/29Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/95361Third Party Advisory, VDB Entry
- https://access.redhat.com/security/vulnerabilities/cve-2016-9962Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1012568#c6Issue Tracking
- https://github.com/docker/docker/releases/tag/v1.12.6Vendor Advisory
- https://github.com/opencontainers/runc/commit/50a19c6ff828c58e5dab13830bd3dacde268afe5Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201701-34Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9962?
How severe is CVE-2016-9962?
How do I fix CVE-2016-9962?
Are you affected by CVE-2016-9962?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
