UBUNTU-CVE-2019-19921

    Dashboard / Vulnerabilities / UBUNTU-CVE-2019-19921

    UBUNTU-CVE-2019-19921

    Published: 12 Feb 2020Last Modified: 4 Feb 2026

    Summary:

    Details: runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

    Affected packages

    Package

    Name: runc

    Purl: pkg:deb/ubuntu/[email protected]~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm4?arch=source&distro=esm-apps/xenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.0~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm4

    Affected versions

    0.0.8+dfsg-2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2019-19921 | CVE-DB