Improper access control in runc - CVE-2019-19921
Published: March 10, 2020 / Updated: March 17, 2020
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions, related to libcontainer/rootfs_linux.go in runc. A local user with ability to spawn two containers with custom volume-mount configurations, and run custom images can escalate privileges on the system.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
SUSE Linux Enterprise Module for Containers
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Opensuse
openSUSE Leap
Ubuntu
openEuler
Fedora
runc (Ubuntu package)
runc (Alpine package)
containerd (Alpine package)
runc (Red Hat package)
toolbox-tests
toolbox
udica
docker-runc
runc
runc-debuginfo
containernetworking-plugins (Red Hat package)
golang-github-opencontainers-runc
slirp4netns
runc-doc
oci-seccomp-bpf-hook
containernetworking-plugins
containerd
netavark
aardvark-dns
crun
skopeo (Red Hat package)
fuse-overlayfs
skopeo
skopeo-tests
cri-o (Red Hat package)
buildah (Red Hat package)
buildah
buildah-tests
containers-common
conmon (Red Hat package)
conmon
nmstate (Red Hat package)
container-selinux (Red Hat package)
container-selinux
openvswitch3.1 (Red Hat package)
criu-devel
python3-criu
criu-libs
criu
crit
libslirp
libslirp-devel
podman (Red Hat package)
python3-podman
podman
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
podman-docker
openshift (Red Hat package)
openshift-ansible (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
docker-debuginfo
docker
openstack-ironic (Red Hat package)
ovn23.06 (Red Hat package)
cockpit-podman
DB2 Data Management Console
DB2 Data Management Console on CPD
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-19921
runc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.0~rc10-0ubuntu1~18.04.2, 1.0.0~rc10-0ubuntu1~19.10.2
runc (Alpine package) - addressed in versions 1.0.0_rc8-r2, 1.0.0_rc10-r0
containerd (Alpine package) - addressed in versions 1.3.0-r0, 1.3.3-r0
runc (Red Hat package) - addressed in versions 1.0.0-66.rc8.el7_7, 1.0.0-66.rc10.rhaos4.3.el7_8, 1.1.6-4.rhaos4.13.el8, 1.1.9-1.el9
DB2 Data Management Console - update to 3.1.13.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.17-sc2, 4.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.1.38, 4.2.22, 4.13.0, 4.13.4
DB2 Data Management Console on CPD - update to 4.7.2
toolbox-tests - addressed in versions 0.0.99.4-5.0.1, 0.0.99.5-2.0.1
toolbox - addressed in versions 0.0.99.4-5.0.1, 0.0.99.5-2.0.1
udica - addressed in versions 0.2.6-20, 0.2.6-21
docker-runc - update to 1.0.0 rc3-229
runc - addressed in versions 1.0.0~rc93-16.8.1, 1.1.5-16.29.1, 1.1.5-150000.41.1
runc-debuginfo - addressed in versions 1.0.0~rc93-16.8.1, 1.1.5-16.29.1, 1.1.5-150000.41.1
runc - addressed in versions 1.0.0-102.dev.gitdc9208a.fc30, 1.0.0-102.dev.gitdc9208a.fc31, 1.1.6-1.fc36, 1.1.6-1.fc37, 1.1.6-1.fc38
containernetworking-plugins (Red Hat package) - addressed in versions 1.0.1-7.rhaos4.13.el8, 1.0.1-8.rhaos4.13.el8
runc - update to 1.1.5-1
golang-github-opencontainers-runc - addressed in versions 1.1.8-1.fc37, 1.1.8-1.fc38, 1.1.8-2.fc37, 1.1.8-2.fc38
runc - addressed in versions 1.1.12-1.0.1, 1.2.5-2, 1.2.8-1, 1.2.9-2
slirp4netns - addressed in versions 1.2.1-1, 1.2.3-1
runc-doc - update to 1.2.8-1
oci-seccomp-bpf-hook - addressed in versions 1.2.9-1, 1.2.10-1
containernetworking-plugins - addressed in versions 1.3.0-8.0.1, 1.4.0-6.0.1
containerd - update to 1.4.4-16.38.1
netavark - addressed in versions 1.7.0-2.0.1, 1.10.3-1.0.1
aardvark-dns - addressed in versions 1.7.0-2.0.1, 1.10.1-2.0.1
crun - addressed in versions 1.8.7-1, 1.14.3-2
skopeo (Red Hat package) - addressed in versions 1.11.2-2.rhaos4.13.el8, 1.11.2-2.1.rhaos4.13.el9
fuse-overlayfs - addressed in versions 1.12-1.0.1, 1.13-1.0.1
skopeo - addressed in versions 1.13.3-3.0.1, 1.14.5-4.0.1, 1.14.5-5
skopeo-tests - addressed in versions 1.13.3-3.0.1, 1.14.5-4.0.1, 1.14.5-5
cri-o (Red Hat package) - addressed in versions 1.26.3-9.rhaos4.13.git994242a.el8, 1.26.3-10.rhaos4.13.git78941bf.el8, 1.26.3-10.rhaos4.13.git994242a.el9, 1.26.3-11.rhaos4.13.git78941bf.el9
buildah (Red Hat package) - addressed in versions 1.29.1-2.rhaos4.13.el8, 1.29.1-2.1.rhaos4.13.el9
buildah - addressed in versions 1.31.3-1, 1.33.12-2, 1.33.13-1
buildah-tests - addressed in versions 1.31.3-1, 1.33.12-2, 1.33.13-1
containers-common - addressed in versions 1-71.0.1, 1-82.0.1
conmon (Red Hat package) - addressed in versions 2.1.7-2.rhaos4.13.el8, 2.1.7-2.1.rhaos4.13.el9
conmon - addressed in versions 2.1.8-1, 2.1.10-1
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.13.el8
container-selinux (Red Hat package) - update to 2.215.0-1.rhaos4.13.el8
container-selinux - addressed in versions 2.221.0-1, 2.229.0-2
openvswitch3.1 (Red Hat package) - update to 3.1.0-32.el9fdp
criu-devel - addressed in versions 3.18-5, 3.18-5.0.1
python3-criu - addressed in versions 3.18-5, 3.18-5.0.1
criu-libs - addressed in versions 3.18-5, 3.18-5.0.1
criu - addressed in versions 3.18-5, 3.18-5.0.1
crit - addressed in versions 3.18-5, 3.18-5.0.1
libslirp - addressed in versions 4.4.0-1, 4.4.0-2
libslirp-devel - addressed in versions 4.4.0-1, 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-4.rhaos4.13.el8, 4.4.1-5.1.rhaos4.13.el9
python3-podman - addressed in versions 4.6.0-1, 4.9.0-3
podman - addressed in versions 4.6.1-8.0.1, 4.9.4-23.0.1, 4.9.4-25.0.2
podman-catatonit - addressed in versions 4.6.1-8.0.1, 4.9.4-23.0.1, 4.9.4-25.0.2
podman-gvproxy - addressed in versions 4.6.1-8.0.1, 4.9.4-23.0.1, 4.9.4-25.0.2
podman-plugins - addressed in versions 4.6.1-8.0.1, 4.9.4-23.0.1, 4.9.4-25.0.2
podman-remote - addressed in versions 4.6.1-8.0.1, 4.9.4-23.0.1, 4.9.4-25.0.2
podman-tests - addressed in versions 4.6.1-8.0.1, 4.9.4-23.0.1, 4.9.4-25.0.2
podman-docker - addressed in versions 4.6.1-8.0.1, 4.9.4-23.0.1, 4.9.4-25.0.2
openshift (Red Hat package) - addressed in versions 4.13.0-202306072143.p0.g7d22122.assembly.stream.el8, 4.13.0-202306072143.p0.g7d22122.assembly.stream.el9, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el8, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202306230038.p0.g148be47.assembly.stream.el8, 4.13.0-202306230038.p0.g148be47.assembly.stream.el9
openshift4-aws-iso (Red Hat package) - update to 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el8, 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9
openshift-kuryr (Red Hat package) - update to 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8
kernel (Red Hat package) - addressed in versions 5.14.0-284.18.1.el9_2, 5.14.0-284.23.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.18.1.rt14.303.el9_2, 5.14.0-284.23.1.rt14.308.el9_2
docker-debuginfo - update to 20.10.6_ce-98.66.1
docker - update to 20.10.6_ce-98.66.1
openstack-ironic (Red Hat package) - update to 21.3.1-0.20230706125653.c8f8157.el9
ovn23.06 (Red Hat package) - update to 23.06.0-13.el9fdp
cockpit-podman - addressed in versions 75-1, 84.1-1
External References
Related Security Bulletins
- Privilege escalation in Open Container runc
- Ubuntu update for runC
- Multiple vulnerabilities in OpenShift Container Platform
- OpenSUSE Linux update for docker-runc
- Gentoo update for runC
- Red Hat Enterprise Linux 7 Extras update for runc
- Amazon Linux AMI update for runc
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Improper access control in containerd (Alpine package)
- Improper access control in runc (Alpine package)
- Red Hat OpenShift Container Platform 4.3 update for runc
- SUSE update for containerd, docker, runc
- SUSE update for runc
- SUSE update for runc
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Ubuntu update for runc
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Fedora 38 update for runc
- Fedora 37 update for runc
- Fedora 36 update for runc
- Fedora 38 update for golang-github-opencontainers-runc
- Fedora 37 update for golang-github-opencontainers-runc
- Fedora 37 update for golang-github-opencontainers-runc
- Fedora 38 update for golang-github-opencontainers-runc
- Red Hat Enterprise Linux 9 update for runc
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Amazon Linux AMI update for runc
- Anolis OS update for container-tools:an8 module
- Fedora 31 update for runc
- Fedora 30 update for runc
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Anolis OS update for container-tools:an8 module
- Anolis OS update for runc
- openEuler update for runc
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in Automation Assets in IBM Cloud Pak for Integration (CP4I)