Alpine: multiple lxc packages: security update to 3.1.0-r1 (deprecated)

high Tenable Self-Hosted Container Security Plugin ID 400491

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite
the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a
command as root within one of these types of containers: (1) a new container with an attacker-controlled
image, or (2) an existing container, to which the attacker previously had write access, that can be
attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
(CVE-2019-5736)

See Also

https://git.alpinelinux.org/aports/commit/?id=ace7331ad9ec031cd70f2778907b58cc2afb4e07

https://git.alpinelinux.org/aports/commit/?id=ebd8ef089dfedbf10cd61204f3a62beb296f7286

Plugin Details

Severity: High

ID: 400491

Version: Revision 1.26

Type: Local

Published: 8/16/2023

Updated: 4/16/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Critical

Score: 9.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2019-5736

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 8.2

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/14/2019

Vulnerability Publication Date: 2/8/2019

Exploitable With

Metasploit (Docker Container Escape Via runC Overwrite)

Reference Information

CVE: CVE-2019-5736

BID: 106976