Container Breaker Vulnerability Discovered
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Docker is a package that deploys software applications within a virtualised environment. It includes the RunC function where the vulnerability lies. If exploited an attacker can escape the confines of the container and gain access to the host machine.
The vulnerability is in the ‘exec’ command, a function that runs an executable in place of the existing process. If running as root, the main processes of the container can gain access to file-descriptors and can lead to container escapes or modification of RunC state before the process is fully placed inside the container.
For further information please see:
Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 11:29 am