Spoofing attack in Docker - CVE-2020-13401
Published: June 3, 2020 / Updated: April 1, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of IPv6 router advertisements. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Affected software
Gentoo Linux
Amazon Linux AMI
Opensuse
Fedora
IBM Cloud Automation Manager
docker.io (Debian package)
docker (Alpine package)
moby-engine
How to mitigate CVE-2020-13401
docker.io (Debian package) - addressed in versions 18.09.1+dfsg1-7.1+deb10u2, 19.03.12+dfsg1-1
docker (Alpine package) - update to 19.03.11-r0
moby-engine - addressed in versions 19.03.11-1.ce.git42e35e6.fc31, 19.03.11-1.ce.git42e35e6.fc32
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Spoofing attack in Docker
- Amazon Linux AMI update for docker
- OpenSUSE Linux update for containerd, docker, docker-runc, golang-github-docker-libnetwork
- Debian update for docker.io
- Spoofing attack in docker (Alpine package)
- Gentoo update for Docker
- Spoofing attack in IBM Cloud Automation Manager
- Spoofing attack in IBM Cloud Automation Manager
- Fedora 32 update for moby-engine
- Fedora 31 update for moby-engine