[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2ECS-2023-015 --- docker

ID: oval:org.secpod.oval:def:1701850Date: (C)2023-11-24   (M)2023-11-24
Class: PATCHFamily: unix




A flaw was found in the `userns-remap` feature of Docker. The root user in the remapped namespace can modify files under /var/lib/docker/less than or remappinggreater than , leading to possible privilege escalation to the root user in the host. The highest threat from this vulnerability is to data integrity. A flaw was found in Docker. Pulling an intentionally malformed Docker image manifest could lead to a crash of the `dockerd` daemon, resulting in a denial of service. The highest threat from this vulnerability is to system availability

Platform:
Amazon Linux 2
Product:
docker
Reference:
ALAS2ECS-2023-015
CVE-2021-21284
CVE-2021-21285
CVE    2
CVE-2021-21285
CVE-2021-21284
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:docker:docker

© SecPod Technologies