MEDIUM
docker: Memory exhaustion via large integer used with --cpuset-mems or --cpuset-cpus
Published Jan 12, 2019
4.9
MEDIUMCVSS 3.0
EPSS 2.23%
Description
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Affected products
No data.
Configuration 2
- 7.0
No data.
Red Hat Enterprise Linux 7 Extras
docker-2:1.13.1-94.gitb2f74b2.el7
Fixed · RHSA-2019:0487
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extras | docker-2:1.13.1-94.gitb2f74b2.el7 | Fixed | RHSA-2019:0487 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of docker as shipped with Red Hat Enterprise Linux 7, however if docker is accessible only by root or highly privileged users, as it is by default, a low-privileged attacker will not be able to trigger the flaw.
Weaknesses (1)
References (7)
- https://access.redhat.com/errata/RHSA-2019:0487 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-20699 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1666565 Issue Tracking
- https://github.com/docker/engine/pull/70 x_refsource_MISCPatchThird Party Advisory
- https://github.com/moby/moby/pull/37967 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-20699
- https://www.cve.org/CVERecord?id=CVE-2018-20699
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:0487 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-20699 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1666565 | Issue Tracking | |
| https://github.com/docker/engine/pull/70 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/moby/moby/pull/37967 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-20699 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-20699 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 12, 2019
Updated Aug 5, 2024
Reserved Jan 11, 2019
Link CVE-2018-20699
CISA Vulnrichment
Updated n/a