Alpine: multiple runc packages: security update to 1.0.0-r0 (deprecated)

high Tenable Cloud Security Plugin ID 400547

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite
the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a
command as root within one of these types of containers: (1) a new container with an attacker-controlled
image, or (2) an existing container, to which the attacker previously had write access, that can be
attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
(CVE-2019-5736)

See Also

https://git.alpinelinux.org/aports/commit/?id=b7b6556c9cf6d775799f425bc3272cda2c7d8e39

https://git.alpinelinux.org/aports/commit/?id=c000685cbe12c9f51e9d651aff660e8b3ebc8f70

Plugin Details

Severity: High

ID: 400547

Version: Revision 1.26

Type: Local

Published: 8/16/2023

Updated: 4/16/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Critical

Score: 9.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2019-5736

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 8.2

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/12/2019

Vulnerability Publication Date: 2/8/2019

Exploitable With

Metasploit (Docker Container Escape Via runC Overwrite)

Reference Information

CVE: CVE-2019-5736

BID: 106976