Bug 1390104 - CVE-2016-8867: ambient capability usage in containers (privilege escalation)
Summary: CVE-2016-8867: ambient capability usage in containers (privilege escalation)
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: docker
Version: 25
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Antonio Murdaca
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Keywords:
Depends On:
Blocks: CVE-2016-8867
TreeView+ depends on / blocked
 
Reported: 2016-10-31 08:14 UTC by Antonio Murdaca
Modified: 2016-11-19 21:13 UTC (History)
13 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2016-11-19 21:05:33 UTC


Attachments (Terms of Use)

Description Antonio Murdaca 2016-10-31 08:14:33 UTC
Description of problem:

privilege escalation: Docker 1.12.2 does not correctly apply user permissions in containers

Version-Release number of selected component (if applicable):

docker-1.12.2

How reproducible:

always


Steps to Reproduce:
1. https://github.com/docker/docker/issues/27590
2.
3.

Actual results:


Expected results:


Additional info:

fixed in docker-1.12.3

Comment 1 Antonio Murdaca 2016-10-31 08:15:12 UTC
fixed in docker-1.12.3 - I'm rebuilding for F25

Comment 2 Fedora Update System 2016-10-31 08:40:45 UTC
docker-1.12.3-2.git91ae1d1.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-8e1558d1c6

Comment 3 Fedora Update System 2016-11-01 02:20:51 UTC
docker-1.12.3-2.git91ae1d1.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-8e1558d1c6

Comment 4 Fedora Update System 2016-11-02 22:34:20 UTC
docker-1.12.3-3.git91ae1d1.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-11c7bec824

Comment 5 Fedora Update System 2016-11-03 13:05:48 UTC
docker-1.12.3-2.git91ae1d1.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-8e1558d1c6

Comment 6 Fedora Update System 2016-11-05 18:56:24 UTC
docker-1.12.3-2.git91ae1d1.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-8e1558d1c6

Comment 7 Fedora Update System 2016-11-05 18:57:42 UTC
docker-1.12.3-3.git91ae1d1.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-11c7bec824

Comment 8 Fedora Update System 2016-11-08 11:42:42 UTC
docker-1.12.3-6.git9a594b9.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-15cf686c8d

Comment 9 Fedora Update System 2016-11-09 02:26:41 UTC
docker-1.12.3-6.git9a594b9.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-15cf686c8d

Comment 10 Fedora Update System 2016-11-19 21:05:33 UTC
docker-1.12.3-2.git91ae1d1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2016-11-19 21:13:49 UTC
docker-1.12.3-6.git9a594b9.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.