← Back to CVE List

CVE-2019-19921

Published: 2020-02-12T15:15Z
Last Modified: 2024-11-21T04:35Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.) > MITRE Terms of Use apply – see LICENSE‑MITRE.txt