Permissions, Privileges, and Access Controls in runc - CVE-2019-16884
Published: November 1, 2019 / Updated: November 21, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect checking of the mount targets in libcontainer/rootfs_linux.go in runc. A local user can bypass AppArmor restrictions and perform unauthorized actions on the system, as demonstrated by overwriting the /proc directory with a malicious Doker image.
Affected software
Docker
Docker Engine
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Containers
Opensuse
Ubuntu
Fedora
runc (Ubuntu package)
runc (Alpine package)
containerd (Alpine package)
runc (Red Hat package)
docker (Red Hat package)
runc-debuginfo
runc
runc-app (Ubuntu package)
containerd
docker-debuginfo
docker
Red Hat OpenShift Container Platform
IBM MQ Operator
IBM supplied MQ Advanced container images
How to mitigate CVE-2019-16884
runc (Ubuntu package) - addressed in versions 1.0.0~rc10-0ubuntu1~18.04.2, 1.0.0~rc10-0ubuntu1~19.10.2
runc (Alpine package) - addressed in versions 1.0.0_rc8-r2, 1.0.0_rc10-r0
containerd (Alpine package) - update to 1.3.0-r0
runc (Red Hat package) - update to 1.0.0-67.rc10.el7_8
docker (Red Hat package) - update to 1.13.1-161.git64e9980.el7_8
Red Hat OpenShift Container Platform - addressed in versions 4.1.24, 4.2.9
runc-debuginfo - update to 1.0.0~rc93-16.8.1
runc - update to 1.0.0~rc93-16.8.1
runc - addressed in versions 1.0.0-95.rc9.gitc1485a1.fc29, 1.0.0-95.rc9.gitc1485a1.fc30, 1.0.0-101.rc9.gitc1485a1.fc31
runc-app (Ubuntu package) - addressed in versions 1.3.3-0ubuntu1~22.04.2, 1.3.3-0ubuntu1~22.04.3, 1.3.3-0ubuntu1~24.04.2, 1.3.3-0ubuntu1~24.04.3, 1.3.3-0ubuntu1~25.04.2, 1.3.3-0ubuntu1~25.04.3, 1.3.3-0ubuntu1~25.10.2, 1.3.3-0ubuntu1~25.10.3
containerd - update to 1.4.4-16.38.1
IBM MQ Operator - addressed in versions 2.0.4, 2.1.0
IBM supplied MQ Advanced container images - update to 9.3.1.0
Docker Engine - update to 19.03.3
docker-debuginfo - update to 20.10.6_ce-98.66.1
docker - update to 20.10.6_ce-98.66.1
External References
Related Security Bulletins
- Privilege scalation in Opencontainers runc
- Privilege escalation in Doker
- OpenSUSE Linux update for docker-runc
- OpenSUSE Linux update for docker-runc
- Privilege escalation in Red Hat OpenShift Container Platform
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Red Hat update for container-tools:rhel8
- OpenSUSE Linux update for containerd, docker, docker-runc, golang-github-docker-libnetwork
- Ubuntu update for runC
- Gentoo update for runC
- Red Hat Enterprise Linux 7 Extras update for docker
- Red Hat Enterprise Linux 7 update for runc
- Permissions, Privileges, and Access Controls in containerd (Alpine package)
- Permissions, Privileges, and Access Controls in runc (Alpine package)
- Amazon Linux AMI update for runc
- Multiple vulnerabilities in IBM MQ Operator
- SUSE update for containerd, docker, runc
- Fedora 31 update for runc
- Fedora 30 update for runc
- Fedora 29 update for runc
- Ubuntu update for runc-app
- Ubuntu update for runc-app