Lucene search

K
redhatRedHatRHSA-2019:0303
HistoryFeb 11, 2019 - 2:24 p.m.

(RHSA-2019:0303) Important: runc security update

2019-02-1114:24:53
access.redhat.com
125

0.004 Low

EPSS

Percentile

73.6%

The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.

Security Fix(es):

  • A flaw was found in the way runc handled system file descriptors when running containers. A malicious container could use this flaw to overwrite contents of the runc binary and consequently run arbitrary commands on the container host system. (CVE-2019-5736)

Additional details about this flaw, including mitigation information, can be found in the vulnerability article linked from the Reference section.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.