Back

HIGH

docker: insecure opening of file-descriptor allows privilege escalation

Published Jan 31, 2017

Description

RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.

Affected products

Remediation

Red Hat mitigation

On Red Hat systems with SELinux enabled, the dangers of even privileged containers are mitigated. SELinux prevents container processes from accessing host content even if those container processes manage to gain access to the actual file descriptors.

Metrics

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 31, 2017
Updated Aug 6, 2024
Reserved Dec 15, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 11, 2017
GHSA-GP4J-W3VJ-7299