Resource exhaustion in Docker - CVE-2021-21285

 

Resource exhaustion in Docker - CVE-2021-21285

Published: February 2, 2021 / Updated: February 3, 2021


Vulnerability identifier: #VU50274
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21285
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trick a victim to pull a specially crafted Docker image, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Docker
Arch Linux
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openEuler
IBM Cloud Automation Manager
docker.io (Debian package)
docker (Alpine package)
runc
runc-debuginfo
containerd
docker-engine
docker
docker-debuginfo
Dell EMC VxRail Appliance
Storage Ceph

How to mitigate CVE-2021-21285

Install updates from vendor's website.

Docker - addressed in versions 19.03.15, 20.10.3
docker.io (Debian package) - update to 18.09.1+dfsg1-7.1+deb10u3
docker (Alpine package) - update to 20.10.3-r0
runc - update to 1.0.0~rc93-16.8.1
runc-debuginfo - update to 1.0.0~rc93-16.8.1
containerd - addressed in versions 1.4.4-5.32.1, 1.4.4-16.38.1
Dell EMC VxRail Appliance - update to 7.0.203
Storage Ceph - update to 7.1
docker-engine - update to 18.09.0-202
docker - update to 20.10.6_ce-98.66.1
docker-debuginfo - update to 20.10.6_ce-98.66.1

External References

Related Security Bulletins