DescriptionAntonio Murdaca
2017-01-11 11:49:20 UTC
Description of problem:
http://seclists.org/oss-sec/2017/q1/54
Docker Engine version 1.12.6 has been released to address a vulnerability
and is immediately available for all supported platforms. Users are advised
to upgrade existing installations of the Docker Engine and use 1.12.6 for
new installations.
Please send any questions to security () docker com.
==============================================================
[CVE-2016-9962] Insecure opening of file-descriptor allows privilege
escalation
==============================================================
RunC allowed additional container processes via `runc exec` to be ptraced
by the pid 1 of the container. This allows the main processes of the
container, if running as root, to gain access to file-descriptors of these
new processes during the initialization and can lead to container escapes
or modification of runC state before the process is fully placed inside the
container
Version-Release number of selected component (if applicable):
How reproducible:
Steps to Reproduce:
1.
2.
3.
Actual results:
Expected results:
Additional info:
Comment 1Fedora Update System
2017-01-11 13:29:43 UTC
Comment 3Fedora Update System
2017-01-13 02:24:08 UTC
docker-1.12.6-3.git51ef5a8.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.