Improper Preservation of Permissions in moby - CVE-2021-41089
Published: June 15, 2022 / Updated: October 19, 2022
Vulnerability identifier: #VU64415
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L]
CVE-ID: CVE-2021-41089
CWE-ID: CWE-281
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.
Affected software
moby
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE MicroOS
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
IBM Edge Application Manager
Dell Secure Connect Gateway
runc
runc-debuginfo
containerd
docker-engine
docker.io (Ubuntu package)
docker
moby-engine
docker-debuginfo
docker-bash-completion
docker-fish-completion
app-containers/docker
SCALANCE LPE9403
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Storage Ceph
IBM InfoSphere Information Server
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE MicroOS
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
IBM Edge Application Manager
Dell Secure Connect Gateway
runc
runc-debuginfo
containerd
docker-engine
docker.io (Ubuntu package)
docker
moby-engine
docker-debuginfo
docker-bash-completion
docker-fish-completion
app-containers/docker
SCALANCE LPE9403
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Storage Ceph
IBM InfoSphere Information Server
How to mitigate CVE-2021-41089
Install updates from vendor's website.
moby - update to 20.10.9
Dell Secure Connect Gateway - update to 5.12.00.10
runc - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
runc-debuginfo - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
containerd - addressed in versions 1.4.11-16.45.1, 1.4.11-56.1, 1.4.12-16.49.1, 1.4.12-60.1
containerd - addressed in versions 1.5.7-1.fc34, 1.5.7-1.fc35
SCALANCE LPE9403 - update to 2.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Storage Ceph - update to 7.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
docker-engine - update to 18.09.0-238
docker.io (Ubuntu package) - addressed in versions 20.10.7-0ubuntu1~18.04.2, 20.10.7-0ubuntu1~20.04.2, 20.10.7-0ubuntu1~21.04.2
docker - update to 20.10.7-3.71
moby-engine - addressed in versions 20.10.9-1.fc34, 20.10.9-1.fc35
docker-debuginfo - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker-bash-completion - update to 20.10.12_ce-159.1
docker-fish-completion - update to 20.10.12_ce-159.1
app-containers/docker - update to 25.0.4
Dell Secure Connect Gateway - update to 5.12.00.10
runc - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
runc-debuginfo - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
containerd - addressed in versions 1.4.11-16.45.1, 1.4.11-56.1, 1.4.12-16.49.1, 1.4.12-60.1
containerd - addressed in versions 1.5.7-1.fc34, 1.5.7-1.fc35
SCALANCE LPE9403 - update to 2.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Storage Ceph - update to 7.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
docker-engine - update to 18.09.0-238
docker.io (Ubuntu package) - addressed in versions 20.10.7-0ubuntu1~18.04.2, 20.10.7-0ubuntu1~20.04.2, 20.10.7-0ubuntu1~21.04.2
docker - update to 20.10.7-3.71
moby-engine - addressed in versions 20.10.9-1.fc34, 20.10.9-1.fc35
docker-debuginfo - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker-bash-completion - update to 20.10.12_ce-159.1
docker-fish-completion - update to 20.10.12_ce-159.1
app-containers/docker - update to 25.0.4
External References
- https://github.com/moby/moby/commit/bce32e5c93be4caf1a592582155b9cb837fc129a
- https://github.com/moby/moby/security/advisories/GHSA-v994-f8vw-g7j4
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNFADTCHHYWVM6W4NJ6CB4FNFM2VMBIB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5Q6G6I4W5COQE25QMC7FJY3I3PAYFBB/
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
Related Security Bulletins
- Multiple vulnerabilities in Moby
- Multiple vulnerabilities in Siemens SCALANCE LPE9403
- SUSE update for containerd, docker, runc
- SUSE update for containerd, docker, runc
- Ubuntu update for docker.io
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- SUSE update for containerd, docker
- SUSE update for containerd, docker
- Amazon Linux AMI update for docker
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- openEuler update for docker
- Multiple vulnerabilities in IBM Storage Ceph
- Gentoo update for Docker
- Fedora 35 update for containerd, moby-engine
- Fedora 34 update for containerd, moby-engine
- Multiple vulnerabilities in IBM InfoSphere Information Server