Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-19921
Description:runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2022.1550   1.3.6.1.4.1.25623.1.1.2.2023.1800   1.3.6.1.4.1.25623.1.1.10.2023.0125   1.3.6.1.4.1.25623.1.1.2.2023.1818   1.3.6.1.4.1.25623.1.1.2.2023.2680   1.3.6.1.4.1.25623.1.0.853037   1.3.6.1.4.1.25623.1.0.877443   1.3.6.1.4.1.25623.1.1.2.2023.1617   1.3.6.1.4.1.25623.1.1.2.2022.1762   1.3.6.1.4.1.25623.1.1.4.2020.0375.1   1.3.6.1.4.1.25623.1.1.4.2020.0376.1   1.3.6.1.4.1.25623.1.1.2.2022.1585   1.3.6.1.4.1.25623.1.1.10.2020.0103   1.3.6.1.4.1.25623.1.1.4.2023.2003.1   1.3.6.1.4.1.25623.1.1.2.2023.2638   1.3.6.1.4.1.25623.1.1.1.2.2023.3369  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-19921
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I6BF24VCZRFTYBTT3T7HDZUOTKOTNPLZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DHGVGGMKGZSJ7YO67TGGPFEHBYMS63VF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYVE3GB4OG3BNT5DLQHYO4M5SXX33AQ5/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNB2UEDIIJCRQW4WJLZOPQJZXCVSXMLD/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANUGDBJ7NBUMSUFZUSKU3ZMQYZ2Z3STN/
https://security.gentoo.org/glsa/202003-21
https://github.com/opencontainers/runc/issues/2197
https://github.com/opencontainers/runc/pull/2190
https://github.com/opencontainers/runc/releases
https://security-tracker.debian.org/tracker/CVE-2019-19921
https://lists.debian.org/debian-lts-announce/2023/03/msg00023.html
RedHat Security Advisories: RHSA-2020:0688
https://access.redhat.com/errata/RHSA-2020:0688
RedHat Security Advisories: RHSA-2020:0695
https://access.redhat.com/errata/RHSA-2020:0695
SuSE Security Announcement: openSUSE-SU-2020:0219 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00018.html
https://usn.ubuntu.com/4297-1/




© 1998-2025 E-Soft Inc. All rights reserved.