Improper access control in containerd - CVE-2020-15257
Published: December 1, 2020 / Updated: January 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict access to the abstract Unix domain socket. This would allow malicious containers running in the same network namespace as the shim, with an effective UID of 0 but otherwise reduced privileges, to cause new processes to be run with elevated privileges.
Affected software
Storage Ceph
Gentoo Linux
Arch Linux
Ubuntu
openEuler
Fedora
containerd (Alpine package)
docker.io (Debian package)
docker (Alpine package)
containerd
containerd (Ubuntu package)
golang-github-docker-containerd-dev (Ubuntu package)
golang-github-containerd-containerd-dev (Ubuntu package)
IBM MQ Operator
Red Hat OpenStack
How to mitigate CVE-2020-15257
containerd (Alpine package) - update to 1.4.3-r0
IBM MQ Operator - update to 2.0.0
docker.io (Debian package) - update to 18.09.1+dfsg1-7.1+deb10u3
docker (Alpine package) - update to 19.03.14-r0
containerd - update to 1.2.0-102
containerd (Ubuntu package) - addressed in versions 1.2.6-0ubuntu1~16.04.5, 1.2.6-0ubuntu1~16.04.6, 1.3.3-0ubuntu1~18.04.3, 1.3.3-0ubuntu1~18.04.4, 1.3.3-0ubuntu2.1, 1.3.3-0ubuntu2.2, 1.3.7-0ubuntu3.1, 1.3.7-0ubuntu3.2
golang-github-docker-containerd-dev (Ubuntu package) - addressed in versions 1.2.6-0ubuntu1~16.04.6, 1.3.3-0ubuntu1~18.04.4, 1.3.3-0ubuntu2.2
golang-github-containerd-containerd-dev (Ubuntu package) - update to 1.3.7-0ubuntu3.2
containerd - update to 1.4.3-1.fc33
Storage Ceph - update to 7.1
Red Hat OpenStack - update to 16.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Privilege escalation in containerd
- Arch Linux update for containerd
- Improper access control in docker (Alpine package)
- Improper access control in containerd (Alpine package)
- Debian update for docker.io
- Gentoo update for containerd
- Ubuntu update for containerd
- Multiple vulnerabilities in IBM MQ Operator
- openEuler 20.03 LTS update for containerd
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Ubuntu update for containerd
- Fedora 33 update for containerd