CVE-2016-9962

RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2017-0116.html
http://rhn.redhat.com/errata/RHSA-2017-0123.html
http://rhn.redhat.com/errata/RHSA-2017-0127.html
http://seclists.org/fulldisclosure/2017/Jan/21 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jan/29 Mailing List Third Party Advisory
http://www.securityfocus.com/archive/1/540001/100/0/threaded
http://www.securityfocus.com/bid/95361 Third Party Advisory VDB Entry
https://access.redhat.com/security/vulnerabilities/cve-2016-9962 Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1012568#c6 Issue Tracking
https://github.com/docker/docker/releases/tag/v1.12.6 Vendor Advisory
https://github.com/opencontainers/runc/commit/50a19c6ff828c58e5dab13830bd3dacde268afe5 Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAXJMMLRU7DD2IMG47SR2K4BOFFG7FZ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FINGBFMIXBG6B6ZWYH3TMRP5V3PDBNXR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UVM7FCOQMPKOFLDTUYSS4ES76DDM56VP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WUQ3MQNEL5IBZZLMLR72Q4YDCL2SCKRK/
https://security.gentoo.org/glsa/201701-34 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0116.html
http://rhn.redhat.com/errata/RHSA-2017-0123.html
http://rhn.redhat.com/errata/RHSA-2017-0127.html
http://seclists.org/fulldisclosure/2017/Jan/21 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jan/29 Mailing List Third Party Advisory
http://www.securityfocus.com/archive/1/540001/100/0/threaded
http://www.securityfocus.com/bid/95361 Third Party Advisory VDB Entry
https://access.redhat.com/security/vulnerabilities/cve-2016-9962 Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1012568#c6 Issue Tracking
https://github.com/docker/docker/releases/tag/v1.12.6 Vendor Advisory
https://github.com/opencontainers/runc/commit/50a19c6ff828c58e5dab13830bd3dacde268afe5 Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAXJMMLRU7DD2IMG47SR2K4BOFFG7FZ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FINGBFMIXBG6B6ZWYH3TMRP5V3PDBNXR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UVM7FCOQMPKOFLDTUYSS4ES76DDM56VP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WUQ3MQNEL5IBZZLMLR72Q4YDCL2SCKRK/
https://security.gentoo.org/glsa/201701-34 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:02

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2017-0116.html - () http://rhn.redhat.com/errata/RHSA-2017-0116.html -
References () http://rhn.redhat.com/errata/RHSA-2017-0123.html - () http://rhn.redhat.com/errata/RHSA-2017-0123.html -
References () http://rhn.redhat.com/errata/RHSA-2017-0127.html - () http://rhn.redhat.com/errata/RHSA-2017-0127.html -
References () http://seclists.org/fulldisclosure/2017/Jan/21 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2017/Jan/21 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2017/Jan/29 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2017/Jan/29 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/archive/1/540001/100/0/threaded - () http://www.securityfocus.com/archive/1/540001/100/0/threaded -
References () http://www.securityfocus.com/bid/95361 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/95361 - Third Party Advisory, VDB Entry
References () https://access.redhat.com/security/vulnerabilities/cve-2016-9962 - Third Party Advisory () https://access.redhat.com/security/vulnerabilities/cve-2016-9962 - Third Party Advisory
References () https://bugzilla.suse.com/show_bug.cgi?id=1012568#c6 - Issue Tracking () https://bugzilla.suse.com/show_bug.cgi?id=1012568#c6 - Issue Tracking
References () https://github.com/docker/docker/releases/tag/v1.12.6 - Vendor Advisory () https://github.com/docker/docker/releases/tag/v1.12.6 - Vendor Advisory
References () https://github.com/opencontainers/runc/commit/50a19c6ff828c58e5dab13830bd3dacde268afe5 - Patch, Third Party Advisory () https://github.com/opencontainers/runc/commit/50a19c6ff828c58e5dab13830bd3dacde268afe5 - Patch, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAXJMMLRU7DD2IMG47SR2K4BOFFG7FZ/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAXJMMLRU7DD2IMG47SR2K4BOFFG7FZ/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FINGBFMIXBG6B6ZWYH3TMRP5V3PDBNXR/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FINGBFMIXBG6B6ZWYH3TMRP5V3PDBNXR/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UVM7FCOQMPKOFLDTUYSS4ES76DDM56VP/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UVM7FCOQMPKOFLDTUYSS4ES76DDM56VP/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WUQ3MQNEL5IBZZLMLR72Q4YDCL2SCKRK/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WUQ3MQNEL5IBZZLMLR72Q4YDCL2SCKRK/ -
References () https://security.gentoo.org/glsa/201701-34 - Third Party Advisory () https://security.gentoo.org/glsa/201701-34 - Third Party Advisory

Information

Published : 2017-01-31 22:59

Updated : 2024-11-21 03:02


NVD link : CVE-2016-9962

Mitre link : CVE-2016-9962

CVE.ORG link : CVE-2016-9962


JSON object : View

Products Affected

docker

  • docker
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')