Permissions, Privileges, and Access Controls in runc - CVE-2019-16884

 

Permissions, Privileges, and Access Controls in runc - CVE-2019-16884

Published: November 1, 2019 / Updated: November 21, 2019


Vulnerability identifier: #VU22482
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-16884
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect checking of the mount targets in libcontainer/rootfs_linux.go in runc. A local user can bypass AppArmor restrictions and perform unauthorized actions on the system, as demonstrated by overwriting the /proc directory with a malicious Doker image.


Affected software

runc
Docker
Docker Engine
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Containers
Opensuse
Ubuntu
Fedora
runc (Ubuntu package)
runc (Alpine package)
containerd (Alpine package)
runc (Red Hat package)
docker (Red Hat package)
runc-debuginfo
runc
runc-app (Ubuntu package)
containerd
docker-debuginfo
docker
Red Hat OpenShift Container Platform
IBM MQ Operator
IBM supplied MQ Advanced container images

How to mitigate CVE-2019-16884

Install updates from vendor's website.

runc - update to 1.0.0 rc9
runc (Ubuntu package) - addressed in versions 1.0.0~rc10-0ubuntu1~18.04.2, 1.0.0~rc10-0ubuntu1~19.10.2
runc (Alpine package) - addressed in versions 1.0.0_rc8-r2, 1.0.0_rc10-r0
containerd (Alpine package) - update to 1.3.0-r0
runc (Red Hat package) - update to 1.0.0-67.rc10.el7_8
docker (Red Hat package) - update to 1.13.1-161.git64e9980.el7_8
Red Hat OpenShift Container Platform - addressed in versions 4.1.24, 4.2.9
runc-debuginfo - update to 1.0.0~rc93-16.8.1
runc - update to 1.0.0~rc93-16.8.1
runc - addressed in versions 1.0.0-95.rc9.gitc1485a1.fc29, 1.0.0-95.rc9.gitc1485a1.fc30, 1.0.0-101.rc9.gitc1485a1.fc31
runc-app (Ubuntu package) - addressed in versions 1.3.3-0ubuntu1~22.04.2, 1.3.3-0ubuntu1~22.04.3, 1.3.3-0ubuntu1~24.04.2, 1.3.3-0ubuntu1~24.04.3, 1.3.3-0ubuntu1~25.04.2, 1.3.3-0ubuntu1~25.04.3, 1.3.3-0ubuntu1~25.10.2, 1.3.3-0ubuntu1~25.10.3
containerd - update to 1.4.4-16.38.1
IBM MQ Operator - addressed in versions 2.0.4, 2.1.0
IBM supplied MQ Advanced container images - update to 9.3.1.0
Docker Engine - update to 19.03.3
docker-debuginfo - update to 20.10.6_ce-98.66.1
docker - update to 20.10.6_ce-98.66.1

External References

Related Security Bulletins