Skip to main content

Container Breaker Vulnerability Discovered

Docker and other similar container software packages contain a vulnerability that can allow access to the host device.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Docker and other similar container software packages contain a vulnerability that can allow access to the host device.

Threat details

Docker is a package that deploys software applications within a virtualised environment. It includes the RunC function where the vulnerability lies. If exploited an attacker can escape the confines of the container and gain access to the host machine.

The vulnerability is in the ‘exec’ command, a function that runs an executable in place of the existing process. If running as root, the main processes of the container can gain access to file-descriptors and can lead to container escapes or modification of RunC state before the process is fully placed inside the container.

For further information please see:

CVE-2016-9962


Remediation steps

Type Step
  • Ensure patches are applied to all container applications containing the RunC tool.
  • Monitor distribution providers for patch availability.
  • Deploy Intrusion Detection Systems capable of detecting unauthorised resource access from the container to the host.


CVE Vulnerabilities

Last edited: 17 February 2020 11:29 am